Dual-Connectivity Key Realignment for Inactive UE Resume

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In dual connectivity scenarios, user equipment (UE) fails to properly align security keys for DRBs and SRBs when transitioning from an inactive state to a connected state, leading to incorrect encryption support.

Innovation Solution

The UE generates a new KSN key based on the current value of KMN and sk-Counter, and derives new security keys such as KUPenc and KRRCint, while the MN and SN generate aligned KMN and KSN keys to ensure consistent encryption across radio bearers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Use of energy by moving object

If the UE retains stored AS context when transitioning to inactive state, then power saving is improved, but security key alignment is lost

Engineering Contradiction:
Improvepower savingVSAvoidsecurity key alignment
Core Design Contradiction:
Use of energy by moving objectVSReliability

Solution Approach 1:

The patent applies preliminary action by having the UE and network side generate and align new security keys (KMN and KSN) before the UE actually resumes the radio connection. The network generates the new KMN key and derives the new KSN key in advance, then transmits the new KSN key to the UE before resumption. This ensures that when the UE resumes from inactive state, both sides already have the aligned security keys ready, eliminating the key alignment problem while maintaining the power saving benefits of the inactive state.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If the UE uses different security keys for MN and SN, then security coverage is improved, but key management complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidkey management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by separating the security key management into distinct components: a master node key (KMN) that is common to both MN and SN, and a secondary node key (KSN) that is specific to the SN. This segmentation allows the UE to manage different security keys for different nodes (improving security coverage) while using a hierarchical derivation structure that reduces the overall management complexity compared to having completely independent key sets.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies the nested doll principle through the hierarchical key derivation structure where the KSN key is derived from the KMN key using a key derivation function. This nesting relationship (KSN derived from KMN) allows the system to maintain secure independent keys for each node while using a hierarchical structure that reduces management complexity by establishing clear dependency relationships between keys.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Speed

If the UE resumes radio connection without key realignment, then connection speed is improved, but encryption security is compromised

Engineering Contradiction:
Improveconnection speedVSAvoidencryption security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent applies preliminary action by performing the security key generation and alignment operations before the UE resumes the radio connection. The network generates the new KMN key and derives the new KSN key in advance, then transmits the new KSN key to the UE before resumption. This ensures that when the UE resumes, both sides already have the aligned security keys ready, allowing the UE to resume connection quickly without compromising encryption security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12532164B2Managing security keys in a communication system
Publication Date: 2026.01.20 GOOGLE LLC
  • US12532164B2 patent drawing
  • US12532164B2 patent drawing
  • US12532164B2 patent drawing

AI summary

A security key management method can be implemented a user equipment (UE) capable of concurrent communication with a master node (MN) and a secondary node (SN). The method includes transitioning (504) from a connected state in which the UE communicates with the MN using a first security key and with the SN using a second security key (502), to an inactive state in which a radio connection between the UE and a radio access network (RAN) is suspended. The method further includes performing a procedure for transitioning from the inactive state to the connected state, including generating a new RAN key KSN corresponding to the SN (506) and generating a new security key for communicating with the SN based on at least the new RAN key KSN (508).