Early Data Transmission Security Framework for Key Synchronization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing radio access network (RAN) security frameworks, particularly in 3GPP LTE and 5G networks, face challenges in efficiently managing key derivations and security procedures during early data transmission (EDT), leading to potential key mismatches and security issues when UE transitions between different network entities that support or do not support EDT.
Innovation Solution
The proposed solution involves enhanced key handling mechanisms, including vertical and horizontal key derivations based on the Next Hop Chaining Counter (NCC) values, to ensure secure and synchronized key generation for UE connections across different network entities, even when EDT is not supported by all entities involved.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If enhanced key handling mechanisms with vertical and horizontal key derivations are implemented, then key synchronization across network entities is maintained and security is improved, but device complexity and procedure overhead increase
Solution Approach 1:
The key derivation process is segmented into two distinct types: vertical key derivation (used when EDT is not supported) and horizontal key derivation (used when EDT is supported). This segmentation allows each derivation type to be optimized for its specific use case, maintaining security while managing complexity through structured differentiation of key handling procedures based on network entity capabilities
Solution Approach 2:
The key handling mechanism dynamically adapts between vertical and horizontal derivation modes based on whether the network entity supports EDT. The system transitions between different key derivation strategies depending on operational context, enabling flexible security management that responds to changing network conditions and entity capabilities
2Reliability
If key derivations are performed based on NCC values during EDT, then security is enhanced, but processing time and computational overhead increase
Solution Approach 1:
Keys are derived in advance during the EDT procedure using NCC values before actual data transmission occurs. By performing key derivation as a preliminary action during the random access procedure, the system ensures security is established beforehand, avoiding delays during critical data transmission phases
3Productivity
If early data transmission is supported, then productivity is improved, but security risks increase due to potential key mismatches
Solution Approach 1:
The NCC value serves as an intermediary parameter that enables secure key derivation during EDT. By using NCC as the basis for key derivation, the system facilitates efficient data transmission while maintaining security through a trusted intermediate mechanism that ensures both UE and network entity derive matching keys
Solution Approach 2:
The system changes the NCC parameter value across different derivation instances, ensuring that each key derivation produces a unique, synchronized key pair. This parameter change mechanism prevents key mismatches by ensuring both parties use the same evolving NCC values for consistent key generation
Data Source
AI summary
Systems and methods of a security framework for an RRC connection are described. The UE receives a release message that comprises a current Next Hop Chaining Counter (NCC). The UE derives a new KeNB* using the current NCC and transmits an EDT RA preamble to same or a different base station. After receiving an RAR with an uplink allocation, the UE transmits a RRCConnectionResumeRequest message. The UE transmits uplink data encrypted using KeNB* if the uplink allocation includes a data allocation sufficient for the data, fall backs to a legacy RRC connection procedure in which the stored KeNB* is discarded and then KeNB* is re-derived if the data allocation is insufficient for the data due to a CE level change, and fall backs to a legacy RRC connection procedure in which the stored KeNB* is used instead of discarding KeNB* if the uplink allocation excludes the data allocation.


