Dual Connectivity Security Key Management in LTE Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security mechanisms for dual connectivity in LTE networks face issues with key separation and repetition, leading to potential security compromises, especially during handovers and changes in serving cell groups, which can expose user plane data to attacks and fail to detect intruder packets effectively.
Innovation Solution
The method involves establishing and updating security contexts between User Equipment (UE) and secondary eNodeBs (SeNBs) using RRC and X2 signaling, with the master eNodeB (MeNB) managing key refresh and countercheck procedures to prevent key repetition and detect packet injection attacks, ensuring secure communication and key separation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing security mechanisms are used for dual connectivity, then authentication and authorization can be performed, but key separation and repetition issues arise leading to security compromises
Solution Approach 1:
The patent segments the security key management by introducing separate base keys for MeNB (K_eNB_M) and SeNB (K_eNB_S). This segmentation prevents key repetition and ensures key separation between the master and secondary base stations, directly resolving the security vulnerability in existing mechanisms.
Solution Approach 2:
The patent performs preliminary key derivation and configuration before dual connectivity operations. The MeNB derives the SeNB base key in advance using a key derivation function with unique inputs (eNB ID, PCI, frequency), and configures the UE with necessary parameters before the UE connects to SeNB, preventing security issues during dynamic connectivity changes.
2Reliability
If security keys are updated during handovers and serving cell group changes, then security is maintained, but key repetition may occur exposing user plane data to attacks
Solution Approach 1:
The patent changes the parameters used in key derivation to ensure uniqueness. The SeNB base key is derived using a key derivation function that incorporates eNB ID, physical cell identity (PCI), and frequency as unique inputs. This parameter change ensures that each SeNB configuration generates a distinct base key, preventing key repetition during handovers and serving cell group changes.
3Reliability
If intruder detection mechanisms are implemented, then packet injection attacks can be detected, but system complexity increases
Solution Approach 1:
The patent implements a feedback mechanism where the MeNB monitors and verifies PDCP counters reported by the SeNB. The MeNB compares the reported counter values with expected values based on its own PDCP entity state, providing continuous feedback to detect packet injection attacks. This feedback-based approach enables intruder detection without requiring complex additional detection systems.
Data Source
Figure 1~2b
Figure 3~4
Figure 5
AI summary
A system and method provide a security aspect for a UE in dual connectivity mode of operation in wireless communication networks. The system and method provide secure simultaneous transmission and reception in a secure manner between a User Equipment (UE) and one or more eNodeBs (eNBs) configured in an inter-eNB carrier aggregation scenario. The system establishes of a security context between the UE and the Secondary eNB (SeNB) using the RRC signaling between the UE and the Master eNB (MeNB), when a plurality of SCells within SeNB are added simultaneously. The system also detects the intruder in the user data radio bearers, while a UE is operating in dual connectivity mode of operation.