Inter-CU LTM Security Keys via MAC-CE Counters
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing New Radio (NR) technologies lack support for inter-centralized unit (CU) lower layer triggered mobility (LTM) in secondary node (SN) changes, necessitating secure exchange of security-related information without relying on Radio Resource Control (RRC) or Medium Access Control (MAC) messages.
Innovation Solution
Utilizing a modified Medium Access Control (MAC) control element (MAC-CE) to convey counter parameters or indices for deriving security keys, enabling secure inter-CU LTM in SN changes without RRC or MAC messages, and employing secure RRC configurations for key derivation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If inter-CU LTM is supported, then security key exchange capability is improved, but signaling overhead increases due to additional security-related information exchange
Solution Approach 1:
The patent combines security key exchange information with existing MAC-CE signaling structures used for LTM operations. By merging security parameters into the MAC-CE format already required for mobility triggering, the patent avoids separate dedicated signaling messages, thereby reducing overall signaling overhead while enabling inter-CU LTM security key exchange capability
Solution Approach 2:
The MAC-CE signaling element is designed to serve multiple functions simultaneously: it triggers LTM operations and conveys security key derivation parameters. This multi-functional approach eliminates the need for separate RRC or MAC messages dedicated solely to security information exchange, reducing signaling overhead while improving adaptability
2Reliability
If security key derivation is enabled for inter-CU LTM, then communication security is improved, but processing complexity increases due to key derivation operations
Solution Approach 1:
The patent performs security key derivation operations in advance during RRC configuration phases, preparing key material before LTM operations are triggered. This preliminary key preparation reduces processing complexity during actual LTM execution, as the UE and network nodes already have the necessary key derivation materials ready when mobility events occur
Solution Approach 2:
The patent introduces counter values and key derivation parameters as intermediary elements that facilitate secure key generation without requiring complex real-time cryptographic operations during LTM. These intermediaries (counter values, pre-configured parameters) simplify the key derivation process while maintaining communication security
3Loss of time
If MAC-CE is used for triggering SN change, then latency is reduced, but security information exposure risk increases
Solution Approach 1:
The patent changes the parameter encoding format in MAC-CE from direct security key material to derived counter values and indices. This parameter transformation maintains the low-latency advantage of MAC-CE triggering while reducing security exposure, as the transmitted parameters are mathematical derivatives rather than direct representations of sensitive key material
Solution Approach 2:
The patent converts the potential security risk of MAC-CE transmission into a benefit by using the MAC-CE's brevity and speed to transmit only essential counter parameters rather than full security keys. The 'harm' of using MAC-CE (potential exposure) is transformed into a 'blessing' by designing the message to contain only minimal, non-sensitive parameters that still enable secure key derivation
Data Source
AI summary
An apparatus configured to process, based on signaling received from a first serving cell, a configuration for New Radio dual connectivity (NR-DC) operation in which the first serving cell is a master node (MN) and a second serving cell is a secondary node (SN), the configuration including at least one candidate SN for lower layer triggered mobility (LTM), process, based on signaling received from the SN, a medium access control (MAC) control element (MAC-CE) that triggers a SN change to a first candidate SN, the MAC-CE including a counter value for deriving a security key of the first candidate SN, derive the security key for the first candidate SN based on the counter value and perform operations associated with the SN change from the SN to the first candidate SN.


