DAPS Handover SRB1 COUNT Management to Prevent Keystream Reuse

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Keystream reuse during Dual Active Protocol Stack (DAPS) handover in 5G networks can lead to exposure of confidential data due to the reuse of security keys and initialization vectors, compromising the security of signaling radio bearers (SRB1) when handover fails and the UE falls back to the source cell.

Innovation Solution

Maintain sequential incrementation of the DL/UL COUNT value for SRB1 during both handover to the target cell and fallback to the source cell, ensuring that each PDCP packet is encrypted with a unique initialization vector, thereby preventing keystream reuse.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If security key is retained during DAPS handover to improve performance, then encryption overhead is reduced, but keystream reuse occurs compromising security

Engineering Contradiction:
Improvehandover performanceVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the COUNT value management by creating separate PDCP entities for source and target cells, each with independent COUNT counters. This segmentation prevents keystream reuse while maintaining security key retention, as each PDCP entity generates unique keystreams for its respective cell

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter management approach by maintaining sequential incrementation of COUNT values across handover events. Instead of resetting COUNT during handover, the system continues incrementing from the previous value, ensuring unique initialization vectors for each encryption operation while retaining the security key

Inventive Principle:
Principle #35Parameter changes

2Device complexity

If COUNT value is reset during handover to simplify state management, then protocol complexity is reduced, but security is compromised due to keystream reuse

Engineering Contradiction:
Improveprotocol state managementVSAvoidkeystream reuse
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by establishing separate PDCP entities for source and target cells before handover occurs. Each entity is pre-configured with its own COUNT counter, ensuring that when handover happens, the sequential incrementation is already in place and keystream reuse is prevented without complex runtime state management

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent adds a dimensional separation by creating distinct PDCP entity instances for source and target cells. This dimensional change transforms the problem from managing a single COUNT state to managing multiple independent COUNT states, preventing keystream reuse while maintaining simplicity through clear separation of concerns

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Object-affected harmful factors

If separate PDCP entities are maintained for source and target cells to prevent keystream reuse, then security is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidPDCP entity management
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies self-service by making each PDCP entity autonomous with its own COUNT counter that automatically increments. The entities independently manage their own state without requiring complex coordination or synchronization mechanisms, reducing overall system complexity while maintaining security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent discards the source PDCP entity's COUNT state when handover completes and recovers resources. This allows the system to maintain security during the transition period with separate entities while returning to a simpler single-entity state after handover, minimizing long-term complexity

Inventive Principle:
Principle #34Discarding and recovering

Data Source

PatentEP4319300B1Radio network node, user equipment (UE) and methods performed therein
Publication Date: 2026.04.08 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP4319300B1 patent drawingFigure 1
  • EP4319300B1 patent drawingFigure 2
  • EP4319300B1 patent drawingFigure 3

AI summary

Embodiments herein relate to for example a method performed by a radio network node for handling a communication of a user equipment, UE, in a wireless communication network. The radio network node transmits a handover command for handing over the UE, from a source cell to a target cell, wherein a security parameter for encrypting data communicated between the radio network node and the UE is retained during the handover. Furthermore the radio network node maintains a sequence number status for reception and/or transmission of a signalling radio bearer of the UE during the handover from the source cell to the target cell, and/or at a fallback from the target cell to the source cell, when the UE triggers the fallback to the source cell.