HetNet Gateway Security Key Synchronization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In LTE networks, security key synchronization issues during handovers between eNodeBs lead to failures in RRC connection re-establishment, as existing methods fail to derive fresh security keys effectively, especially when gateways serve multiple eNodeBs and are oblivious to mobility procedures.

Innovation Solution

A method for a HetNet Gateway (HNG) to retrieve fresh security key context from the Mobility Management Entity (MME) by simulating an X2 handover procedure, using message exchanges to obtain a fresh Next Hop and Next Hop Chaining Count pair, ensuring key synchronization between UE and target eNodeB.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If gateways retrieve security keys from EPC without deriving them locally, then the gateway implementation is simpler, but handover failures occur due to key synchronization issues between UE and target eNodeB

Engineering Contradiction:
Improvegateway implementation simplicityVSAvoidhandover success rate
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The gateway is enhanced to perform self-service by locally deriving security keys using the horizontal key derivation procedure. Instead of merely retrieving keys from EPC, the gateway now autonomously generates fresh security keys during handover procedures, ensuring key synchronization between UE and target eNodeB while maintaining implementation feasibility

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The gateway performs preliminary key derivation actions before handover execution. By pre-computing fresh security keys using the horizontal derivation procedure and storing them in advance, the gateway ensures that target eNodeB has synchronized keys ready before the actual handover occurs, preventing handover failures

Inventive Principle:
Principle #10Preliminary action

2Reliability

If horizontal key derivation is used during RRC connection re-establishment, then key synchronization between UE and eNodeB is achieved, but handover failures occur when gateways serve multiple eNodeBs and are oblivious to mobility procedures

Engineering Contradiction:
Improvekey synchronizationVSAvoidgateway mobility awareness
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The solution segments the key management functionality by introducing a dedicated horizontal key derivation procedure that operates independently within the gateway. This segmentation allows the gateway to handle key derivation for multiple eNodeBs separately, maintaining key synchronization without requiring the gateway to be fully aware of all mobility procedures across different eNodeBs

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The gateway changes the operational parameters of key derivation by implementing the horizontal procedure specifically for RRC connection re-establishment scenarios. This parameter change enables the gateway to generate appropriate security keys based on local context rather than relying on EPC-provided keys, improving adaptability to multi-eNodeB environments

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11638181B2Method to retrieve security keys of UE in gateways
Publication Date: 2023.04.25 PARALLEL WIRELESS INC
  • US11638181B2 patent drawing
  • US11638181B2 patent drawing
  • US11638181B2 patent drawing

AI summary

Methods, systems, and computer readable media are presented for retrieving security keys in gateways. In one example embodiment, a method is presented. The method of retrieving security keys from a User Equipment (UE) in gateways includes retrieving, by a HetNet Gateway (HNG) as the HNG virtualizes an eNodeB towards n Mobility Management Entity (MME) through a first message and a second message exchange, a fresh Next Hop, Next Hop Chaining Count {NH, NCC} pair from the MME; and mocking, by the HNG, an X2 handover towards the MME by sending a third message with required Information Elements filled when a fourth message from the eNodeB reaches the HNG.