Conditional Handover Security Context Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication systems lack efficient and effective methods for implementing conditional handovers in 5G networks, particularly in managing radio link failures and security configurations during handover processes.

Innovation Solution

The implementation of conditional handover configurations, where a wireless terminal receives reconfiguration messages with candidate target cell identities and triggering conditions, allowing autonomous handover decisions based on radio link failures, and the use of security configurations to establish and validate security contexts during handovers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conditional handover configurations are provided to wireless terminals for autonomous handover decisions, then handover reliability and robustness are improved, but device complexity and security management burden increase

Engineering Contradiction:
Improvehandover reliabilityVSAvoidsecurity configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The source gNB provides conditional handover configurations including security parameters (K_gNB, NCC, TAG) to the wireless terminal in advance before handover execution. This preliminary provisioning of security configurations enables the terminal to autonomously establish security contexts with target gNBs without requiring real-time security setup, thereby improving handover reliability while managing complexity through pre-computation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The wireless terminal acts as an intermediary that stores and manages multiple conditional handover configurations with associated security parameters. It autonomously selects appropriate configurations based on triggering conditions and executes handovers without real-time network intervention, reducing the security management burden on network operations while maintaining reliability

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If wireless terminals autonomously initiate handovers based on triggering conditions, then handover speed and responsiveness are improved, but loss of information and security validation issues occur

Engineering Contradiction:
Improvehandover speedVSAvoidsecurity context information
Core Design Contradiction:
SpeedVSLoss of information

Solution Approach 1:

The source gNB provides complete security configuration parameters (K_gNB, NCC, TAG) to the wireless terminal in advance as part of the conditional handover configuration. This preliminary provision of security information ensures that when the terminal autonomously executes handover based on triggering conditions, it has all necessary security context information already available, preventing information loss and enabling immediate secure connection establishment

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The wireless terminal provides feedback to the network about the execution of conditional handovers and the validity of security configurations. This feedback mechanism allows the network to verify that terminals have correctly processed and stored security information, and to detect any potential information loss or validation issues before they affect handover reliability

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12089107B2Release of configurations for conditional handovers based on security configurations
Publication Date: 2024.09.10 SHARP KK
  • US12089107B2 patent drawing
  • US12089107B2 patent drawing
  • US12089107B2 patent drawing

AI summary

A wireless terminal comprises processor circuitry and receiver circuitry. The receiver circuitry is configured to receive a configuration message comprising one or more conditional handover configurations. Each of the one or more conditional handover configurations may comprise at least one identity of a candidate target cell, and at least one triggering condition. The processor circuitry is configured to establish, using a first key set, a first security context with a first wireless access node; to perform a handover to a target cell; to determine validity of the conditional handover configurations, based on whether or not the handover to the target cell is configured with a security configuration, and to use the security configuration to derive a second key set for establishing a second security context with a second wireless access node that serves the target cell.