Dual-Connectivity Key Realignment for Inactive UE Resume
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In dual connectivity scenarios, user equipment (UE) fails to properly align security keys for DRBs and SRBs when transitioning from an inactive state to a connected state, leading to incorrect encryption support.
Innovation Solution
The UE generates a new KSN key based on the current value of KMN and sk-Counter, and derives new security keys such as KUPenc and KRRCint, while the MN and SN generate aligned KMN and KSN keys to ensure consistent encryption across radio bearers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Use of energy by moving object
If the UE retains stored AS context when transitioning to inactive state, then power saving is improved, but security key alignment is lost
Solution Approach 1:
The patent applies preliminary action by having the UE and network side generate and align new security keys (KMN and KSN) before the UE actually resumes the radio connection. The network generates the new KMN key and derives the new KSN key in advance, then transmits the new KSN key to the UE before resumption. This ensures that when the UE resumes from inactive state, both sides already have the aligned security keys ready, eliminating the key alignment problem while maintaining the power saving benefits of the inactive state.
2Adaptability or versatility
If the UE uses different security keys for MN and SN, then security coverage is improved, but key management complexity increases
Solution Approach 1:
The patent applies segmentation by separating the security key management into distinct components: a master node key (KMN) that is common to both MN and SN, and a secondary node key (KSN) that is specific to the SN. This segmentation allows the UE to manage different security keys for different nodes (improving security coverage) while using a hierarchical derivation structure that reduces the overall management complexity compared to having completely independent key sets.
Solution Approach 2:
The patent applies the nested doll principle through the hierarchical key derivation structure where the KSN key is derived from the KMN key using a key derivation function. This nesting relationship (KSN derived from KMN) allows the system to maintain secure independent keys for each node while using a hierarchical structure that reduces management complexity by establishing clear dependency relationships between keys.
3Speed
If the UE resumes radio connection without key realignment, then connection speed is improved, but encryption security is compromised
Solution Approach 1:
The patent applies preliminary action by performing the security key generation and alignment operations before the UE resumes the radio connection. The network generates the new KMN key and derives the new KSN key in advance, then transmits the new KSN key to the UE before resumption. This ensures that when the UE resumes, both sides already have the aligned security keys ready, allowing the UE to resume connection quickly without compromising encryption security.
Data Source
AI summary
A security key management method can be implemented a user equipment (UE) capable of concurrent communication with a master node (MN) and a secondary node (SN). The method includes transitioning (504) from a connected state in which the UE communicates with the MN using a first security key and with the SN using a second security key (502), to an inactive state in which a radio connection between the UE and a radio access network (RAN) is suspended. The method further includes performing a procedure for transitioning from the inactive state to the connected state, including generating a new RAN key KSN corresponding to the SN (506) and generating a new security key for communicating with the SN based on at least the new RAN key KSN (508).


