Dual Connectivity Security Key Management in LTE Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security mechanisms for dual connectivity in LTE networks face issues with key separation and repetition, leading to potential security compromises, especially during handovers and changes in serving cell groups, which can expose user plane data to attacks and fail to detect intruder packets effectively.

Innovation Solution

The method involves establishing and updating security contexts between User Equipment (UE) and secondary eNodeBs (SeNBs) using RRC and X2 signaling, with the master eNodeB (MeNB) managing key refresh and countercheck procedures to prevent key repetition and detect packet injection attacks, ensuring secure communication and key separation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing security mechanisms are used for dual connectivity, then authentication and authorization can be performed, but key separation and repetition issues arise leading to security compromises

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security key management by introducing separate base keys for MeNB (K_eNB_M) and SeNB (K_eNB_S). This segmentation prevents key repetition and ensures key separation between the master and secondary base stations, directly resolving the security vulnerability in existing mechanisms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary key derivation and configuration before dual connectivity operations. The MeNB derives the SeNB base key in advance using a key derivation function with unique inputs (eNB ID, PCI, frequency), and configures the UE with necessary parameters before the UE connects to SeNB, preventing security issues during dynamic connectivity changes.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security keys are updated during handovers and serving cell group changes, then security is maintained, but key repetition may occur exposing user plane data to attacks

Engineering Contradiction:
ImprovesecurityVSAvoidkey repetition vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the parameters used in key derivation to ensure uniqueness. The SeNB base key is derived using a key derivation function that incorporates eNB ID, physical cell identity (PCI), and frequency as unique inputs. This parameter change ensures that each SeNB configuration generates a distinct base key, preventing key repetition during handovers and serving cell group changes.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If intruder detection mechanisms are implemented, then packet injection attacks can be detected, but system complexity increases

Engineering Contradiction:
Improveintruder detection capabilityVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a feedback mechanism where the MeNB monitors and verifies PDCP counters reported by the SeNB. The MeNB compares the reported counter values with expected values based on its own PDCP entity state, providing continuous feedback to detect packet injection attacks. This feedback-based approach enables intruder detection without requiring complex additional detection systems.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP2939456B1Dual connectivity mode of operation of a user equipment in a wireless communication network
Publication Date: 2021.03.03 SAMSUNG ELECTRONICS CO LTD
  • EP2939456B1 patent drawingFigure 1~2b
  • EP2939456B1 patent drawingFigure 3~4
  • EP2939456B1 patent drawingFigure 5

AI summary

A system and method provide a security aspect for a UE in dual connectivity mode of operation in wireless communication networks. The system and method provide secure simultaneous transmission and reception in a secure manner between a User Equipment (UE) and one or more eNodeBs (eNBs) configured in an inter-eNB carrier aggregation scenario. The system establishes of a security context between the UE and the Secondary eNB (SeNB) using the RRC signaling between the UE and the Master eNB (MeNB), when a plurality of SCells within SeNB are added simultaneously. The system also detects the intruder in the user data radio bearers, while a UE is operating in dual connectivity mode of operation.