Key Derivation for Handover Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In mobile communication systems, the handover process from one radio access network to another can result in the same key being derived for multiple Radio Network Controllers (RNCs), leading to a network security risk.
Innovation Solution
A method is introduced to derive keys for user equipment (UE) during handovers between radio access networks by using a Key Derivation Function (KDF) with random values, current NAS downlink COUNT values, and root keys, ensuring that each handover generates a unique key.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the same root key and NAS downlink COUNT value are used for key derivation in multiple handover processes, then the key derivation process is simple and consistent, but the same key is derived for multiple RNCs leading to network security risks
Solution Approach 1:
The patent changes the input parameters of the key derivation function by introducing a random value and using a refreshed NAS downlink COUNT value (incremented by 1) instead of reusing the same parameters. This ensures that even when handover fails and retries occur, the derived key will be different, preventing security risks while maintaining a relatively simple derivation process.
2Reliability
If a random value is introduced into the key derivation function, then unique keys are generated for each handover enhancing security, but the key derivation process becomes more complex
Solution Approach 1:
The patent introduces a random value as an additional parameter to the key derivation function. This random value ensures that each handover process generates a unique key, eliminating the security risk of key reuse. The complexity increase is minimal as it only requires generating and transmitting an additional random parameter.
3Reliability
If the NAS downlink COUNT value is refreshed before key derivation, then different keys are derived for different handover attempts, but additional signaling and processing are required
Solution Approach 1:
The patent refreshes the NAS downlink COUNT value by incrementing it by 1 before using it in the key derivation function. This simple parameter change ensures that each handover attempt uses a different COUNT value, resulting in different derived keys. The signaling overhead is minimal as it only requires incrementing a numerical value and including it in the handover command message.
Data Source
AI summary
Method, device, and system for deriving keys are provided in the field of mobile communications technologies. The method for deriving keys may be used, for example, in a handover process of a User Equipment (UE) from an Evolved Universal Terrestrial Radio Access Network (EUTRAN) to a Universal Terrestrial Radio Access Network (UTRAN). If a failure occurred in a first handover, the method ensures that the key derived by a source Mobility Management Entity (MME) for a second handover process of the UE is different from the key derived for the first handover process of the UE. This is done by changing input parameters used in the key derivation, so as to prevent the situation in the prior art that once the key used on one Radio Network Controller (RNC) is obtained, the keys on other RNCs can be derived accordingly, thereby enhancing the network security.


