5G Handover Key Management for Multi-Hop Forward Secrecy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional 5G handover key management mechanisms lack forward security, are vulnerable to de-synchronization and replay attacks, and only achieve two-hops key forward secrecy due to the source gNB's knowledge of the target gNB's access stratum key.
Innovation Solution
A base station and WTRU are configured to derive control plane and user plane security keys based on an access stratum key generated with freshness parameters, using a service-based interface to establish secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If conventional 5G horizontal key derivation is used, then key management is simplified, but forward security is compromised since learning an old key enables derivation of all subsequent keys
Solution Approach 1:
The patent segments the key derivation process into vertical hops through multiple AMF instances, where each AMF derives keys independently from the anchor key rather than horizontally from previous gNB keys. This segmentation breaks the chaining dependency that prevents forward security while maintaining manageable complexity through structured key hierarchy.
Solution Approach 2:
The patent introduces AMF as an intermediary between the anchor key and gNB keys. The AMF acts as a mediator that derives fresh keys for each handover using the anchor key and handover-specific parameters, preventing direct key chaining between gNBs and enabling forward security while simplifying key management at the network core.
2Reliability
If conventional 5G vertical key derivation is used, then forward security is improved, but the source gNB knows the target gNB's access stratum key which limits security to two-hops
Solution Approach 1:
The patent extracts the key derivation function from the source gNB and relocates it to the target AMF. The target AMF independently derives the target gNB's access stratum key using the anchor key and target-specific parameters, preventing the source gNB from knowing the target key while maintaining forward security. This extraction eliminates the two-hop security limitation.
Solution Approach 2:
The patent performs preliminary key derivation at the target AMF before handover execution. The target AMF pre-computes the target gNB's access stratum key using the anchor key and target handover parameters, ensuring the source gNB never obtains this key. This preliminary action at the correct location (target AMF而非source gNB) achieves multi-hop forward secrecy.
3Ease of operation
If conventional key management is used, then system operation is simple, but vulnerability to de-synchronization and replay attacks increases
Solution Approach 1:
The patent performs preliminary key derivation and validation at the target AMF before handover execution. The target AMF pre-computes fresh keys using the anchor key and handover-specific parameters, and validates key consistency before allowing handover. This preliminary secure setup prevents replay attacks and de-synchronization while maintaining operational simplicity through automated procedures.
Solution Approach 2:
The patent changes the key derivation parameters to include fresh handover-specific inputs (target AMF identity, handover counter, target cell information) rather than relying on previous gNB keys. This parameter change ensures each handover generates unique keys, preventing replay attacks while keeping the derivation process simple and automated through standardized algorithms.
Data Source
AI summary
Methods and apparatuses for handover key management are provided according to one or more embodiments. A wireless transmit/receive unit (WTRU) may be handed over from a source base station to a target base station. The source base station may request a handover to a WTRU context management function (UCF). The UCF may generate a freshness parameter associated with the target base station. The UCF may utilize the freshness parameter to generate one or more access stratum (AS) keys. The freshness parameter may be provided to the WTRU by the UCF via the source base station. The WTRU may also utilize the freshness parameter to generate the one or more AS keys. The one or more AS keys may be securely shared with the target base station. The one or more AS keys may be utilized for securing an AS communication between the WTRU and the target base station.


