Dual Connectivity Security Key Management in LTE Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless communication systems face challenges in applying security information effectively in dual connectivity scenarios, particularly in 3GPP LTE networks, where different security information is required for radio bearers served by master and secondary eNodeBs.
Innovation Solution
A method for a user equipment (UE) to obtain and apply distinct security information to radio bearers served by a master eNodeB (MeNB) and a secondary eNodeB (SeNB), including deriving security keys and parameters for secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If dual connectivity is introduced to enhance mobility support and system capacity, then service availability and system capacity are improved, but security management complexity increases due to the need for separate security information application to different radio bearers served by master and secondary eNodeBs
Solution Approach 1:
The patent segments security information management by creating separate security contexts for master eNodeB (MeNB) and secondary eNodeB (SeNB) connections. The UE maintains distinct security information sets including separate integrity protection keys and encryption keys for each eNodeB, allowing independent security management for each connection while supporting dual connectivity functionality.
Solution Approach 2:
The patent applies different security parameters and keys locally to different radio bearers based on their serving eNodeB. Specifically, radio bearers served by MeNB use first security information (K_RRCint, K_RRCenc, K_UPenc for MeNB), while radio bearers served by SeNB use second security information (K_RRCint, K_RRCenc, or K_UPenc for SeNB), ensuring appropriate security protection tailored to each connection's requirements.
2Reliability
If separate security information is applied to different radio bearers served by master and secondary eNodeBs, then security protection is enhanced, but processing overhead and computational requirements increase
Solution Approach 1:
The patent performs preliminary security setup by establishing separate security contexts and deriving all necessary keys (K_RRCint, K_RRCenc, K_UPenc) for both MeNB and SeNB connections during the initial dual connectivity configuration phase. This preliminary action ensures that when data transmission occurs, the UE can efficiently apply pre-configured security parameters without performing complex key derivation operations in real-time, thereby reducing processing overhead during active communication.
Data Source
Figure 1~2
Figure 3~4
Figure 5
AI summary
A method and apparatus for applying security information in a wireless communication system is provided. A user equipment (UE) obtains first security information and second security information, applies the first security information to a first set of radio bearers (RBs) which is served by a master eNodeB (MeNB), and applies the second security information to a second set of RBs which is served by a secondary eNodeB (SeNB).