Handover Authentication Key Derivation for Heterogeneous Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack an efficient mechanism for authentication during handovers between heterogeneous access systems and do not provide a method to generate keys for the evolved system, leading to inefficiencies in network access and security.

Innovation Solution

A method and system for optimizing authentication procedures during inter access system handovers by deriving new keys using existing system access keys, enabling quick re-authentication and secure communication between user equipment and network entities, including mechanisms for forward and backward handovers, and signaling interfaces between MME/UPE and AAA servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication procedures are used during handover between heterogeneous access systems, then security is maintained, but authentication time and network access efficiency deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by performing authentication and key derivation during the handover preparation phase before the actual handover executes. The MME derives new keys (CK*, IK*) using the previous access keys and authentication vectors during preparation, so that when handover occurs, the UE can quickly perform re-authentication using these pre-derived keys, significantly reducing authentication time while maintaining security across heterogeneous access systems.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If new authentication keys are derived during handover preparation, then authentication efficiency improves, but system complexity increases

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent applies universality by creating a multi-functional key derivation mechanism that works across different access systems (UTRAN, E-UTRAN, GERAN, WLAN). The MME uses a universal algorithm that takes previous access keys and authentication vectors to derive new keys for any target access system. This unified approach enables efficient handover between heterogeneous systems without requiring separate authentication mechanisms for each system type, improving efficiency while managing complexity through standardization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If key derivation is performed using previous access keys, then network access efficiency improves, but key management complexity increases

Engineering Contradiction:
Improvenetwork access efficiencyVSAvoidkey management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent applies the intermediary principle by introducing the MME as a centralized key management mediator. The MME receives previous access keys from the source access system, performs secure key derivation using authentication vectors stored in the HSS, and distributes the new derived keys to the target access system and UE. This intermediary approach centralizes key management complexity in the MME/HSS architecture, allowing efficient key derivation for network access while preventing key management complexity from propagating throughout the entire network.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8462742B2System and method for optimizing authentication procedure during inter access system handovers
Publication Date: 2013.06.11 SAMSUNG ELECTRONICS CO LTD
  • US8462742B2 patent drawing
  • US8462742B2 patent drawing
  • US8462742B2 patent drawing

AI summary

Disclosed is a method and system of deriving new keys for accessing a new system. The method enables an optimized authentication procedure during handover form an existing system to a new system by using the existing system access keys. The user equipment that is accessing the new system receives a temporary ID during handover preparation which enables the user equipment to perform a fast re-authentication. The method uses existing system access keys to derive system access keys for the new network.