Dual Connectivity Key Refresh via Master eNB Coordination

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In dual connectivity scenarios with user plane architecture 1A, existing technologies do not effectively address the need to refresh both security keys for the master eNB and secondary eNB, leading to security and communication inefficiencies.

Innovation Solution

A method is proposed to refresh both the master eNB key and secondary eNB key through coordinated RRC connection reconfigurations, where new keys are generated based on freshness values and acknowledged by the user equipment, allowing simultaneous or sequential refreshment of keys without disrupting data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single security key refreshment procedure is used in dual connectivity with architecture 1A, then the key management process is simple, but the security of both MeNB and SeNB connections cannot be simultaneously ensured

Engineering Contradiction:
Improvekey management processVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent divides the key refreshment process into two separate procedures: one for refreshing the MeNB key and another for refreshing the SeNB key. This segmentation allows each key to be refreshed independently with appropriate security measures, ensuring that both connections maintain security while managing complexity through structured separation of the refreshment processes.

Inventive Principle:
Principle #1Segmentation

2Reliability

If separate key refreshment procedures are implemented for MeNB and SeNB, then security is maintained, but the communication overhead and signaling complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidsignaling overhead
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent merges the key refreshment procedures by having the MeNB coordinate both the MeNB key refreshment and SeNB key refreshment through a unified signaling mechanism. The MeNB generates both keys and manages their distribution to the UE and SeNB respectively, reducing signaling overhead by consolidating the coordination function in the MeNB rather than requiring separate independent procedures.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The MeNB performs preliminary actions by generating both the MeNB key and SeNB key in advance, and preparing the necessary signaling information before initiating the refreshment process. This preliminary preparation reduces the need for multiple back-and-forth signaling exchanges during the actual key refreshment, thereby reducing communication overhead.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If key refreshment is performed sequentially to ensure security, then security is maintained, but the time required for key refreshment increases

Engineering Contradiction:
ImprovesecurityVSAvoidkey refreshment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The MeNB generates both the MeNB key and SeNB key in advance before initiating the refreshment process. By preparing both keys preliminarily and including them in the RRC connection reconfiguration message sent to the UE, the system enables parallel processing of key installation at the UE side, reducing the overall time required while maintaining security through proper key derivation and protection mechanisms.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent ensures continuous useful action by maintaining existing key-based security protection during the transition period. The old keys continue to protect data transmission until the new keys are fully installed and confirmed, ensuring that security protection is continuous without interruption while the refreshment process occurs in the background.

Inventive Principle:
Principle #20Continuity of useful action

4Productivity

If the MeNB coordinates both key refreshment processes, then signaling efficiency is improved, but the processing complexity at the MeNB increases

Engineering Contradiction:
Improvesignaling efficiencyVSAvoidMeNB processing complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The MeNB is designed to perform multiple functions including generating both MeNB key and SeNB key, managing their distribution to UE and SeNB, and coordinating the entire refreshment process. This multi-functionality consolidates the coordination burden in a single node (MeNB) that already has the capability to manage dual connectivity, improving signaling efficiency by eliminating the need for additional coordination entities while the MeNB's existing infrastructure handles the increased processing load.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10321308B2Method of refreshing a key in a user plane architecture 1A based dual connectivity situation
Publication Date: 2019.06.11 ALCATEL LUCENT SA
  • US10321308B2 patent drawing
  • US10321308B2 patent drawing
  • US10321308B2 patent drawing

AI summary

The invention provides a method of refreshing a key in a user plane architecture 1A based dual connectivity situation. According to an embodiment of the present invention, a method, in a secondary eNB in a dual connectivity communication scenario, of refreshing a key, is provided, wherein a user equipment, a master eNB and a secondary eNB form dual connectivity, a user plane architecture 1A is applied for the dual connectivity, and the master eNB uses a master eNB key, the secondary eNB uses a secondary eNB key, the method comprises following steps: —receiving a new secondary eNB key from the master eNB; —receiving a key fresh complete from the master eNB, which indicates the user equipment has refreshed the secondary eNB key; —implementing a random access procedure with the user equipment; and —refreshing the secondary eNB key with the new secondary eNB key, and implementing data transmission with the user equipment with the new secondary eNB key.