Key Set Identifier Mapping for Seamless Network Handover
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
When a user equipment (UE) transfers from an evolved UMTS terrestrial radio access network (EUTRAN) to a universal terrestrial radio access network (UTRAN) or a global system for mobile communications (GSM) or an enhanced data rate for GSM evolution (GERAN) radio access network, the generated keys cannot be reused due to the lack of corresponding identifiers, leading to increased signaling overhead and communication delays.
Innovation Solution
A method and system where the mobility management entity (MME) and UE generate a key set identifier for the target network by mapping the key set identifier of the access security management entity, allowing the MME to send the integrity key and ciphering key along with the identifier to the serving GPRS support node (SGSN), enabling the reuse of keys during transfers between EUTRAN and UTRAN/GERAN.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the UE transfers from EUTRAN to UTRAN or GERAN without key identifier mapping, then the network can maintain simple key management, but the generated keys cannot be reused leading to increased signaling overhead and communication delays
Solution Approach 1:
The patent introduces the key set identifier (KSI) as an intermediary element that bridges the EUTRAN and UTRAN/GERAN key management systems. The MME maps the EUTRAN KASME to a UTRAN KSI, enabling the target network to identify and reuse the mapped key without requiring complex direct key exchange mechanisms between different network types.
Solution Approach 2:
The patent transforms the key identification parameter from the EUTRAN-specific KASME format to a UTRAN-compatible KSI format. This parameter transformation enables seamless key portability across network boundaries by converting the identifier into a format that the target network can recognize and utilize for key reuse.
2Loss of time
If the UE performs AKA authentication for each connection, then security can be ensured, but network resources are wasted and communication time is increased
Solution Approach 1:
The patent performs key mapping and identifier generation as preliminary actions during the handover preparation phase. By pre-establishing the KSI and mapping the KASME before the actual connection is needed, the system avoids the need for time-consuming AKA authentication procedures during subsequent communications, thereby reducing authentication time while maintaining security.
Solution Approach 2:
The patent creates a copy of the security context by mapping the KASME to a KSI that can be recognized by the target network. This copied identifier allows the target network to retrieve and use the corresponding key without requiring the UE to perform full authentication again, thus reducing time loss while preserving security context establishment.
3Device complexity
If the network stores and reuses keys, then signaling overhead is reduced, but the network must manage multiple key identifiers across different networks
Solution Approach 1:
The patent designs the KSI as a universal identifier that serves multiple functions: it identifies keys within UTRAN, enables key portability from EUTRAN, and facilitates key reuse across different network types. This universal design allows the network to manage keys efficiently without requiring separate identification mechanisms for each network type, thereby reducing signaling overhead while maintaining multi-network compatibility.
Data Source
AI summary
A method for generating an identifier of a key, comprises that: when a user equipment (UE) transfers from an evolved UMTS terrestrial radio access network (EUTRAN) to a universal terrestrial radio access network (UTRAN) or a global system for mobile communications (GSM), or an enhanced data rate for GSM evolved radio access network (GERAN), an identifier of a system key after transfer is generated by mapping an identifier KSIASME for an access security management entity, and a mobile management entity generates an identifier of a ciphering key (CK) and an integrity key (IK) by mapping the KSIASME, and then sends the generated identifier to a serving GPRS support node (SGSN), when the UE transfers from the EUTRAN to the UTRAN, the SGSN stores the ciphering key, the integrity key and the identifier thereof, and when the UE transfers from the EUTRAN to the GERAN, the SGSN assigns the value of the identifier of the ciphering key and the integrity key to an identifier of a ciphering key of the GERAN.


