Dual Connectivity Security Keys for Fast Secondary Cell Group Mobility
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 5G dual connectivity operations, significant RRC signaling overhead occurs due to the need for new configuration messages after conditional addition or change of secondary cell groups, limiting fast mobility of user equipment across different SCGs.
Innovation Solution
User equipment autonomously refreshes security keys using a sequence of key counter values received from the master node, enabling secure data exchange without requiring additional network signaling for subsequent cell group changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If new configuration messages are sent for each cell group change, then security keys are refreshed, but RRC signaling overhead increases significantly
Solution Approach 1:
The master node provides the user equipment with advance knowledge of future target secondary nodes and their associated security keys through configuration information. This preliminary preparation allows the user equipment to perform cell group changes without requiring real-time configuration messages from the network, thereby reducing RRC signaling overhead while maintaining security key freshness.
Solution Approach 2:
The user equipment autonomously performs cell group changes by selecting from pre-provided target secondary nodes and security keys without requiring continuous network intervention. The user equipment independently manages the mobility procedure by using the configuration information received earlier, eliminating the need for repeated configuration message exchanges.
2Reliability
If configuration messages are sent before each cell group change, then security is maintained, but fast mobility of user equipment is limited
Solution Approach 1:
The master node performs the security preparation action in advance by providing configuration information that includes future target secondary nodes and their security keys. This allows the user equipment to move between cell groups at high speed without being constrained by real-time configuration message requirements, thus enabling fast mobility while maintaining security through pre-established keys.
Solution Approach 2:
The user equipment independently executes mobility operations by autonomously selecting target secondary nodes from the pre-provided list and using their associated security keys immediately. This self-service capability eliminates the mobility speed bottleneck caused by waiting for network configuration messages, allowing rapid cell group changes without compromising security.
3Reliability
If multiple configuration messages are exchanged, then security keys are updated, but signaling overhead increases
Solution Approach 1:
The master node provides configuration information containing multiple future target secondary nodes and their security keys in advance. This single preliminary action replaces what would otherwise require multiple sequential configuration messages, thereby reducing signaling time while maintaining comprehensive security key management for multiple potential cell group changes.
Solution Approach 2:
The configuration information received from the master node serves multiple functions simultaneously: it prepares the user equipment for security key management, enables autonomous cell group change decisions, and provides future target secondary node information all in one message. This multi-functionality eliminates the need for multiple separate signaling exchanges, reducing overall signaling time.
Data Source
AI summary
The disclosure inter alia relates to a user equipment configured to support dual connectivity operation towards a master node and a secondary node of a radio access network, the user equipment comprising at least one processor and at least one memory, the at least one memory storing instructions that, when executed by the at least one processor, cause the user equipment to perform at least the following: establishing a connection towards the master node; receiving configuration information from the master node, wherein the configuration information comprises key counter information which defines a sequence of at least two different key counter values to generate at least two different security keys for at least two different target secondary nodes.


