Key Derivation for EUTRAN to Enhanced UTRAN Handover
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge is to establish enhanced security keys when a terminal moves from an EUTRAN to an enhanced UTRAN, ensuring secure communication without repeating the Authentication and Key Agreement (AKA) process, which is inefficient and affects system efficiency.
Innovation Solution
The method involves the target enhanced serving GPRS support node (SGSN+) deducing an intermediate key from a mapped traditional key obtained from the source mobility management entity, and the terminal further deducing the intermediate key using the same algorithm, allowing the establishment of enhanced air interface integrity and ciphering keys without repeating the AKA process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the AKA process is repeated when terminal moves from EUTRAN to enhanced UTRAN, then security key establishment is ensured, but system efficiency deteriorates and network overhead increases
Solution Approach 1:
The patent applies preliminary action by pre-establishing the security context and mapping traditional keys to enhanced UTRAN key hierarchy before the terminal actually moves. The source MME prepares the mapped traditional keys (CK', IK') in advance, and the target SGSN+ prepares the intermediate key (K_RNC') beforehand, so that when handover occurs, the enhanced keys can be immediately derived without repeating the full AKA authentication process.
Solution Approach 2:
The patent introduces an intermediary mechanism through the mapped traditional keys (CK', IK') that bridge the EUTRAN and enhanced UTRAN key systems. These mapped keys act as intermediaries that allow the target SGSN+ to derive the intermediate key K_RNC' without requiring the terminal to undergo complete re-authentication, thus maintaining security while improving efficiency during inter-system handover.
2Reliability
If the AKA process is repeated when terminal moves from EUTRAN to enhanced UTRAN, then authentication is ensured, but network overhead increases
Solution Approach 1:
The patent extracts only the essential authentication elements needed for enhanced UTRAN operation. Instead of repeating the complete AKA process, the system extracts the mapped traditional keys (CK', IK') from the source MME and uses them to derive the intermediate key (K_RNC') at the target SGSN+. This extraction approach maintains authentication reliability while minimizing the information and signaling overhead associated with full re-authentication.
3Productivity
If enhanced key hierarchy is established without repeating AKA, then system efficiency improves, but key security may be compromised
Solution Approach 1:
The patent applies preliminary action by pre-establishing the security context and mapping traditional keys to enhanced UTRAN key hierarchy before the terminal actually moves. The source MME prepares the mapped traditional keys (CK', IK') in advance, and the target SGSN+ prepares the intermediate key (K_RNC') beforehand, so that when handover occurs, the enhanced keys can be immediately derived without repeating the full AKA authentication process.
Solution Approach 2:
The patent introduces an intermediary mechanism through the mapped traditional keys (CK', IK') that bridge the EUTRAN and enhanced UTRAN key systems. These mapped keys act as intermediaries that allow the target SGSN+ to derive the intermediate key K_RNC' without requiring the terminal to undergo complete re-authentication, thus maintaining security while improving efficiency during inter-system handover.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
The present invention discloses a method and system for establishing an enhanced key when a terminal moves from an EUTRAN to an enhanced UTRAN, so as to ensure that the terminal can carry out normal communication safely in the enhanced UTRAN. The method includes: when the terminal moves from the EUTRAN to the enhanced UTRAN, a target enhanced serving GPRS support node (SGSN+) in the enhanced UTRAN deducing an intermediate key used in the UTRAN according to a mapped traditional key obtained from a source mobile management entity; and the terminal, after deducing the mapped traditional key, further deduces the intermediate key used in the enhanced UTRAN by using an algorithm which is the same as that of the target SGSN+ according to the mapped traditional key.