Inter-eNB Carrier Aggregation Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security frameworks in LTE and LTE-Advanced networks are inadequate for supporting key generation in inter-eNB carrier aggregation systems, as they assume a single serving eNB, which is not applicable in scenarios involving multiple eNBs.

Innovation Solution

A system and method for secure radio access with inter-eNB carrier aggregation, where a primary eNB generates a base key and derives a set of keys, which are then shared with secondary eNBs to secure transmission, ensuring secure communication across multiple eNBs without increasing signaling overhead or complexity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single base key KeNB is used for a UE-eNB pair as in traditional LTE security framework, then security is maintained for single eNB scenarios, but inter-eNB carrier aggregation cannot be supported

Engineering Contradiction:
Improvesupport for inter-eNB carrier aggregationVSAvoidsecurity framework reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the security key management by introducing multiple base keys (one for each serving eNB) instead of a single KeNB. Each base key is specific to a UE-eNB pair, allowing the system to support multiple eNBs simultaneously while maintaining security. This segmentation enables inter-eNB carrier aggregation by providing distinct cryptographic identities for each eNB serving the UE.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a new dimension to the security framework by extending it from single-eNB to multi-eNB scenarios. Instead of modifying the existing KeNB in place, it introduces a dimensional expansion where multiple base keys coexist, each operating in its own UE-eNB pair context. This dimensional change allows the system to handle inter-eNB carrier aggregation without compromising the original security model.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If multiple base keys are generated for inter-eNB carrier aggregation, then security is enhanced for multiple eNBs, but key management complexity increases

Engineering Contradiction:
Improvesecurity for multiple eNBsVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service in key management where each eNB independently generates its own base key for the UE-eNB pair. The keys are derived autonomously using the eNB's identity and the UE's identity, eliminating the need for complex centralized key distribution mechanisms. This self-service approach reduces key management complexity while maintaining security across multiple eNBs.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal key derivation mechanism that works for both single-eNB and inter-eNB carrier aggregation scenarios. The same key derivation function is used regardless of whether one or multiple eNBs are serving the UE, providing multi-functionality. This universal approach simplifies key management by using a consistent procedure across different deployment scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If derived keys are distributed to multiple eNBs, then secure transmission is enabled across eNBs, but signaling overhead increases

Engineering Contradiction:
Improvesecure transmission across eNBsVSAvoidsignaling overhead
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts only the necessary cryptographic material (base keys and derived keys) that each eNB needs to perform secure transmission. Instead of distributing all possible keys or extensive security parameters, it extracts and transmits only the specific base key for each UE-eNB pair and the derived keys necessary for that eNB's communication with the UE. This extraction minimizes signaling overhead while ensuring security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs preliminary key derivation at each eNB before transmission begins. Each eNB pre-computes the base key and necessary derived keys based on its identity and the UE's identity, so that when data transmission starts, the keys are already in place. This preliminary action eliminates the need for extensive real-time key exchange signaling during data transmission, reducing overhead.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10433162B2Secure radio access with inter-eNB carrier aggregation
Publication Date: 2019.10.01 NTT DOCOMO INC
  • US10433162B2 patent drawing
  • US10433162B2 patent drawing
  • US10433162B2 patent drawing

AI summary

A system for securing radio access with inter-eNB carrier aggregation including a primary eNB configured to secure transmission with a user equipment. The primary eNB generates a base key and derives a set of derived keys used to secure transmission on a set of radio bearers that correspond to the set of derived keys. The system for securing radio access with inter-eNB carrier aggregation also including a secondary eNB configured to secure transmission with the UE using at least one of the set of derived keys received which corresponds to a radio bearer from the set of radio bearers used by the SeNB.