Cryptographic Key Separation for Mobile Handovers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile communication networks, such as E-UTRAN, face security issues during handovers due to lack of cryptographic key separation, allowing previous evolved node-Bs to derive encryption keys used by mobile terminals and serving evolved node-Bs, compromising data security.
Innovation Solution
Implementing a method that provides cryptographic key separation by configuring the SGSN to include an intermediary key in the path switch acknowledgement message, allowing the target access point to derive a cryptographically separate key using a key derivation function, and sending a handover command with indications for intra- or inter-access point handovers to protect path switch messages.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption key is communicated from source evolved node-B to target evolved node-B during handover, then handover continuity is maintained, but cryptographic key separation security is compromised
Solution Approach 1:
The encryption key material is segmented into multiple components: the source evolved node-B contributes first information (e.g., part of the key or key derivation material), the target evolved node-B contributes second information (e.g., cell identity, hop counter), and the mobile terminal contributes third information (e.g., authentication data). These segments are combined through a key derivation function to produce the final encryption key, ensuring that no single node possesses the complete key material and thus maintaining cryptographic key separation while enabling handover continuity.
2Object-affected harmful factors
If intermediary key is included in path switch acknowledgement message, then cryptographic key separation is achieved, but processing overhead and data transfer overhead increase
Solution Approach 1:
The patent modifies existing protocol message parameters rather than introducing entirely new message types. The intermediary key is embedded within the existing path switch acknowledgement message structure, and the handover command is enhanced with a handover type indication parameter. This approach achieves cryptographic key separation while minimizing increases in data transfer overhead by reusing existing message frameworks and adding only essential new parameters.
3Object-affected harmful factors
If key derivation function uses multiple input parameters from different sources, then cryptographic key separation is improved, but processing complexity increases
Solution Approach 1:
The patent employs a universal key derivation function that can process multiple types of input parameters from different sources (source evolved node-B information, target evolved node-B information, mobile terminal information) through a single standardized algorithmic framework. This multi-functional approach achieves cryptographic key separation while controlling processing complexity by using one versatile derivation mechanism rather than multiple specialized functions.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method, apparatus and computer program product are provided to provide cryptographical key separation for handovers. A method is provided which includes calculating a key based at least in part upon a previously stored first intermediary value. The method also includes calculating a second intermediary value based at least in part upon the calculated key. The method additionally includes sending a path switch acknowledgement including the second intermediary value to a target access point. The method may further include receiving a path switch message including an indication of a cell identification and calculating the encryption key based upon the indication of the cell identification. The method may further include storing the second intermediary value. The calculation of the key may further comprise calculating the key following a radio link handover. Corresponding apparatuses and computer program products are also provided.