Key Set Identifier Mapping for Seamless Network Handover

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

When a user equipment (UE) transfers from an evolved UMTS terrestrial radio access network (EUTRAN) to a universal terrestrial radio access network (UTRAN) or a global system for mobile communications (GSM) or an enhanced data rate for GSM evolution (GERAN) radio access network, the generated keys cannot be reused due to the lack of corresponding identifiers, leading to increased signaling overhead and communication delays.

Innovation Solution

A method and system where the mobility management entity (MME) and UE generate a key set identifier for the target network by mapping the key set identifier of the access security management entity, allowing the MME to send the integrity key and ciphering key along with the identifier to the serving GPRS support node (SGSN), enabling the reuse of keys during transfers between EUTRAN and UTRAN/GERAN.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the UE transfers from EUTRAN to UTRAN or GERAN without key identifier mapping, then the network can maintain simple key management, but the generated keys cannot be reused leading to increased signaling overhead and communication delays

Engineering Contradiction:
Improvekey reuse capabilityVSAvoididentifier mapping mechanism
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces the key set identifier (KSI) as an intermediary element that bridges the EUTRAN and UTRAN/GERAN key management systems. The MME maps the EUTRAN KASME to a UTRAN KSI, enabling the target network to identify and reuse the mapped key without requiring complex direct key exchange mechanisms between different network types.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms the key identification parameter from the EUTRAN-specific KASME format to a UTRAN-compatible KSI format. This parameter transformation enables seamless key portability across network boundaries by converting the identifier into a format that the target network can recognize and utilize for key reuse.

Inventive Principle:
Principle #35Parameter changes

2Loss of time

If the UE performs AKA authentication for each connection, then security can be ensured, but network resources are wasted and communication time is increased

Engineering Contradiction:
Improveauthentication timeVSAvoidsecurity context establishment
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The patent performs key mapping and identifier generation as preliminary actions during the handover preparation phase. By pre-establishing the KSI and mapping the KASME before the actual connection is needed, the system avoids the need for time-consuming AKA authentication procedures during subsequent communications, thereby reducing authentication time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a copy of the security context by mapping the KASME to a KSI that can be recognized by the target network. This copied identifier allows the target network to retrieve and use the corresponding key without requiring the UE to perform full authentication again, thus reducing time loss while preserving security context establishment.

Inventive Principle:
Principle #26Copying

3Device complexity

If the network stores and reuses keys, then signaling overhead is reduced, but the network must manage multiple key identifiers across different networks

Engineering Contradiction:
Improvesignaling overheadVSAvoidmulti-network key compatibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent designs the KSI as a universal identifier that serves multiple functions: it identifies keys within UTRAN, enables key portability from EUTRAN, and facilitates key reuse across different network types. This universal design allows the network to manage keys efficiently without requiring separate identification mechanisms for each network type, thereby reducing signaling overhead while maintaining multi-network compatibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8750515B2Method and system for generating an identifier of a key
Publication Date: 2014.06.10 ZTE CORP
  • US8750515B2 patent drawing
  • US8750515B2 patent drawing
  • US8750515B2 patent drawing

AI summary

A method for generating an identifier of a key, comprises that: when a user equipment (UE) transfers from an evolved UMTS terrestrial radio access network (EUTRAN) to a universal terrestrial radio access network (UTRAN) or a global system for mobile communications (GSM), or an enhanced data rate for GSM evolved radio access network (GERAN), an identifier of a system key after transfer is generated by mapping an identifier KSIASME for an access security management entity, and a mobile management entity generates an identifier of a ciphering key (CK) and an integrity key (IK) by mapping the KSIASME, and then sends the generated identifier to a serving GPRS support node (SGSN), when the UE transfers from the EUTRAN to the UTRAN, the SGSN stores the ciphering key, the integrity key and the identifier thereof, and when the UE transfers from the EUTRAN to the GERAN, the SGSN assigns the value of the identifier of the ciphering key and the integrity key to an identifier of a ciphering key of the GERAN.