Conditional Cell Change Security Key Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the context of multi-random access technology dual connectivity (MR-DC) with selective activation of cell groups, there is a need to determine a security key for subsequent conditional primary secondary cell (CPC) changes after the initial CPC/conditional primary secondary cell addition (CPA) procedure, as the security key generated during the initial RRC reconfiguration is used only once.
Innovation Solution
The method involves receiving a conditional reconfiguration from a first network device indicating that a subsequent conditional cell change is enabled. A first counter value, different from the second counter value used for the initial cell change or addition, is determined. Based on this first counter value, a security key is determined for communication with a second network device providing the candidate cell for the subsequent conditional cell change.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of energy
If the same security key is reused for subsequent conditional cell changes, then signaling overhead is reduced, but security is compromised
Solution Approach 1:
The patent segments the security key generation process by introducing a counter parameter that varies for each conditional cell change. The security key is derived as a function of the initial security key and the counter value (KsN' = f(KsN, counter)), creating distinct security keys for different cell changes while maintaining a structured relationship that reduces signaling overhead.
Solution Approach 2:
The patent changes the parameter space by introducing a counter variable that modifies the security key derivation. Instead of using a static security key, the system uses a dynamic key derivation function that incorporates the counter parameter, allowing security keys to change based on the cell change instance while being generated from the same initial parameters.
2Reliability
If a new security key is generated for each cell change, then security is enhanced, but signaling overhead increases
Solution Approach 1:
The patent performs preliminary action by pre-configuring the counter parameter and the security key derivation function during the initial RRC reconfiguration. The terminal device is provided with the initial security key and the counter value, and the derivation function is established in advance, allowing subsequent cell changes to generate unique security keys without additional network signaling.
Solution Approach 2:
The terminal device performs self-service by autonomously generating the security key for conditional cell changes using the pre-configured initial security key and counter parameter. The terminal applies the derivation function locally without requiring network intervention, thereby enhancing security while minimizing signaling overhead.
3Device complexity
If the counter value is reused, then device complexity is reduced, but security is compromised
Solution Approach 1:
The patent applies universality by using a single counter parameter that serves multiple functions: it identifies the specific conditional cell change instance, drives the security key derivation, and can be reused across different scenarios (CPA and CPC procedures). This single counter manages both security differentiation and procedure identification without requiring separate counters for different functions.
Data Source
AI summary
Embodiments of the present disclosure relate to methods, devices and computer readable media for communication. A terminal device receives, from a first network device, a conditional reconfiguration indicating that a subsequent conditional cell change is enabled. If the subsequent conditional cell change to a candidate cell is to be performed after a cell change or addition is performed, the terminal device determines a first counter value, the first counter value being different from a second counter value used for the cell change or addition, and determines, based on the first counter value, a security key for communication with a second network device providing the candidate cell. In this way, a security key is determined for a subsequent conditional cell change.


