Cellular Handover Security Context Generation Across Network Nodes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cellular communication systems, handovers from older equipment to newer equipment, such as from 2G/3G to 4G, face challenges in transferring necessary security information, leading to disruptions during call handovers due to incompatibilities between different types of communication equipment.

Innovation Solution

A method where a first node generates a security context for a client by receiving cryptographic keys and identities of security algorithms from other nodes, allowing seamless handovers by creating a new security context that is compatible with the target equipment, specifically in the packet switched domain.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Stability of the object's composition

If handover is performed from older equipment to newer equipment, then service continuity is improved, but call disruptions occur due to security context incompatibilities

Engineering Contradiction:
Improveservice continuityVSAvoidcall disruption
Core Design Contradiction:
Stability of the object's compositionVSReliability

Solution Approach 1:

The target node performs preliminary actions by proactively requesting security algorithm identities from the source node before the actual handover occurs. This allows the target node to prepare the appropriate security context in advance, ensuring compatibility when the handover executes, thereby preventing call disruptions while maintaining service continuity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism where the source node acts as a mediator by providing security algorithm identity information to the target node. This intermediary exchange of security context information enables the target node to construct the correct security parameters, resolving the incompatibility issue between older and newer equipment during handover.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security context is transferred during handover, then security compatibility is improved, but information loss occurs due to incompatibilities between different equipment types

Engineering Contradiction:
Improvesecurity compatibilityVSAvoidsecurity information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts only the essential security information needed for compatibility - specifically the security algorithm identities - from the source node and transfers them to the target node. This selective extraction approach ensures that the target node receives the necessary security context without being overwhelmed by incompatible information from older equipment, thereby preventing information loss while maintaining security compatibility.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the parameter representation by transforming security context information into a standardized format of algorithm identities that can be universally understood by both older and newer equipment. This parameter transformation ensures that security information is preserved and correctly interpreted during the handover process, preventing information loss while achieving security compatibility.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10433161B2Call handover between cellular communication system nodes that support different security contexts
Publication Date: 2019.10.01 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US10433161B2 patent drawing
  • US10433161B2 patent drawing
  • US10433161B2 patent drawing

AI summary

In the context of facilitating a circuit switched to packet switched handover of a call in a cellular communication system, a first node (e.g., packet switched target node) generates a security context for a client whose call is being handed over. This involves the first node receiving at least one cryptographic key from a second node (e.g., a circuit switched node supporting the existing connection) and receiving identities of security algorithms supported by the client from a third node (e.g., a packet switched node supporting the existing connection); The first node uses the at least one cryptographic key and the identities to generate the security context for the client.