Dual Connectivity Key Refresh via Master eNB Coordination
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In dual connectivity scenarios with user plane architecture 1A, existing technologies do not effectively address the need to refresh both security keys for the master eNB and secondary eNB, leading to security and communication inefficiencies.
Innovation Solution
A method is proposed to refresh both the master eNB key and secondary eNB key through coordinated RRC connection reconfigurations, where new keys are generated based on freshness values and acknowledged by the user equipment, allowing simultaneous or sequential refreshment of keys without disrupting data transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a single security key refreshment procedure is used in dual connectivity with architecture 1A, then the key management process is simple, but the security of both MeNB and SeNB connections cannot be simultaneously ensured
Solution Approach 1:
The patent divides the key refreshment process into two separate procedures: one for refreshing the MeNB key and another for refreshing the SeNB key. This segmentation allows each key to be refreshed independently with appropriate security measures, ensuring that both connections maintain security while managing complexity through structured separation of the refreshment processes.
2Reliability
If separate key refreshment procedures are implemented for MeNB and SeNB, then security is maintained, but the communication overhead and signaling complexity increase
Solution Approach 1:
The patent merges the key refreshment procedures by having the MeNB coordinate both the MeNB key refreshment and SeNB key refreshment through a unified signaling mechanism. The MeNB generates both keys and manages their distribution to the UE and SeNB respectively, reducing signaling overhead by consolidating the coordination function in the MeNB rather than requiring separate independent procedures.
Solution Approach 2:
The MeNB performs preliminary actions by generating both the MeNB key and SeNB key in advance, and preparing the necessary signaling information before initiating the refreshment process. This preliminary preparation reduces the need for multiple back-and-forth signaling exchanges during the actual key refreshment, thereby reducing communication overhead.
3Reliability
If key refreshment is performed sequentially to ensure security, then security is maintained, but the time required for key refreshment increases
Solution Approach 1:
The MeNB generates both the MeNB key and SeNB key in advance before initiating the refreshment process. By preparing both keys preliminarily and including them in the RRC connection reconfiguration message sent to the UE, the system enables parallel processing of key installation at the UE side, reducing the overall time required while maintaining security through proper key derivation and protection mechanisms.
Solution Approach 2:
The patent ensures continuous useful action by maintaining existing key-based security protection during the transition period. The old keys continue to protect data transmission until the new keys are fully installed and confirmed, ensuring that security protection is continuous without interruption while the refreshment process occurs in the background.
4Productivity
If the MeNB coordinates both key refreshment processes, then signaling efficiency is improved, but the processing complexity at the MeNB increases
Solution Approach 1:
The MeNB is designed to perform multiple functions including generating both MeNB key and SeNB key, managing their distribution to UE and SeNB, and coordinating the entire refreshment process. This multi-functionality consolidates the coordination burden in a single node (MeNB) that already has the capability to manage dual connectivity, improving signaling efficiency by eliminating the need for additional coordination entities while the MeNB's existing infrastructure handles the increased processing load.
Data Source
AI summary
The invention provides a method of refreshing a key in a user plane architecture 1A based dual connectivity situation. According to an embodiment of the present invention, a method, in a secondary eNB in a dual connectivity communication scenario, of refreshing a key, is provided, wherein a user equipment, a master eNB and a secondary eNB form dual connectivity, a user plane architecture 1A is applied for the dual connectivity, and the master eNB uses a master eNB key, the secondary eNB uses a secondary eNB key, the method comprises following steps: —receiving a new secondary eNB key from the master eNB; —receiving a key fresh complete from the master eNB, which indicates the user equipment has refreshed the secondary eNB key; —implementing a random access procedure with the user equipment; and —refreshing the secondary eNB key with the new secondary eNB key, and implementing data transmission with the user equipment with the new secondary eNB key.


