Conditional Secondary Cell Configuration Release via Key Rotation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless communication systems, particularly in 5G networks, face challenges in efficiently implementing conditional handovers to secondary cell groups (SCG) for enhanced reliability and robustness, as existing methods lack efficient mechanisms for secure context establishment and dynamic configuration management during handover processes.
Innovation Solution
The implementation of a wireless terminal and access node system that uses Access Stratum (AS) master keys to establish and manage security contexts for conditional secondary cell group configurations, including derivation of new security keys and dynamic release of configurations based on key changes, enabling autonomous handover decisions by the UE based on received configuration parameters.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conditional handover configurations are stored permanently in the wireless terminal, then handover reliability is improved, but security vulnerability increases when master keys change
Solution Approach 1:
The patent implements dynamic management of conditional handover configurations by releasing them when the master key changes. The wireless terminal stores configurations during their validity period but automatically releases them when key rotation occurs, transforming from static permanent storage to dynamic conditional storage based on security state.
Solution Approach 2:
The patent changes the parameter of configuration validity based on key state. When the master key changes, the validity parameter of stored configurations is updated to expire, causing them to be released. This parameter change resolves the contradiction by linking storage duration to security requirements.
2Object-affected harmful factors
If security key rotation is implemented frequently, then security strength is improved, but handover configuration management complexity increases
Solution Approach 1:
The wireless terminal autonomously manages configuration release based on key changes without requiring network intervention. The terminal monitors its own key state and automatically releases configurations when rotation occurs, implementing self-service that reduces network-side management complexity.
Solution Approach 2:
The system implements feedback mechanisms where the wireless terminal monitors key changes and responds by releasing configurations. This feedback loop enables automatic adaptation to security state changes, simplifying management compared to manual configuration updates.
3Speed
If autonomous handover decisions are enabled by the UE, then handover speed is improved, but control complexity increases
Solution Approach 1:
The network performs preliminary actions by providing the wireless terminal with pre-configured candidate target cell information and handover conditions before actual handover is needed. The terminal stores these configurations and autonomously executes handover when conditions are met, eliminating the need for real-time network decisions and improving speed.
Solution Approach 2:
The patent segments the handover control function by dividing responsibilities: the network provides configuration parameters and candidate cells, while the terminal autonomously monitors conditions and executes handover decisions. This segmentation enables UE autonomy without requiring the terminal to manage all handover aspects.
Data Source
AI summary
A wireless terminal includes processor circuitry configured to establish, using a first master key, a first security context on a first radio connection with a master access node, and receiver circuitry configured to receive a re-configuration message including one or more conditional secondary cell configurations and at least one counter. Each conditional secondary cell configuration may include an identity of a candidate primary secondary cell and at least one triggering condition, the candidate primary secondary cell being used for Dual-Connectivity. The at least one counter and the first master key may be used for derivation of a second master key to be used for an establishment of a second security context with one of candidate primary secondary cells. The processor circuitry is further configured to invalidate the one or more conditional secondary cell configurations upon a change of the first master key.


