Key Derivation for 2G-3G to LTE Handover Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the transition of user equipment from a 2G/3G communication system to LTE, there is a need to derive separate keys for Access Stratum (AS), Non-Access Stratum (NAS) signalling protection, and User-plane (U-plane) protection, which existing technologies do not effectively address.

Innovation Solution

A method is provided to calculate a set of associated keys for the authentication process in the LTE network using identities of network entities and a random value from the 2G/3G network, allowing for the generation of ciphering and integrity protection keys for AS, NAS, and U-plane protection, without requiring changes to the AKA protocol or the home subscriber server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate keys for AS, NAS, and U-plane protection are derived during handover from 2G/3G to LTE, then security protection is improved, but key derivation complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidkey derivation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the key derivation process into distinct components: deriving CK and IK from the random value RAND using the first network's AKA protocol, then separately deriving AS key, NAS key, and U-plane key from CK and IK using the second network's entity identities. This segmentation allows each key to be derived independently for its specific protection purpose, improving security while managing complexity through structured organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary key derivation by obtaining CK and IK from the first network's authentication process before the handover to the second network. These pre-derived keys (CK and IK) serve as the foundation for subsequently deriving the three separate protection keys (AS, NAS, U-plane) in the second network, eliminating the need to perform complete authentication again and reducing overall derivation complexity.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple separate keys are generated for different protection layers, then security is improved, but the number of keys increases

Engineering Contradiction:
ImprovesecurityVSAvoidnumber of keys
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges the security functionality of multiple keys by deriving AS key, NAS key, and U-plane key from a common foundation (CK and IK obtained through AKA authentication). Rather than requiring entirely separate authentication processes for each protection layer, the system combines them through a hierarchical key derivation structure where three specific keys are systematically generated from the same authentication credentials, reducing the total number of keys needed.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The derived keys serve multiple functions within the LTE network: CK and IK obtained from the first network are universally used as the basis for deriving AS key (for RRC signaling protection), NAS key (for NAS signaling protection), and U-plane key (for user data protection). This multi-functionality allows a single authentication process to support multiple security requirements across different protocol layers.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If key derivation uses identities of network entities from the second network, then adaptability is improved, but calculation complexity increases

Engineering Contradiction:
ImproveadaptabilityVSAvoidcalculation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by using specific identities of network entities from the second network (such as eNB identity for AS protection, MME identity for NAS protection, and UPE identity for U-plane protection) in the key derivation process. Each key derivation operation incorporates the relevant local identity appropriate to that specific protection layer, ensuring that keys are tailored to their specific security context while maintaining a systematic derivation process from the common CK and IK foundation.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3761598B1Generating keys for protection in next generation mobile networks
Publication Date: 2023.12.20 NOKIA TECHNOLOGIES OY
  • EP3761598B1 patent drawingFigure 1
  • EP3761598B1 patent drawingFigure 2
  • EP3761598B1 patent drawingFigure 3

AI summary

A user equipment comprises: a receiving unit for receiving identities of network entities of a second network during a handover process of the user equipment from a first network to the second network; and a calculating unit for calculating a set of associated keys for an authentication process to be performed in the second network using the identities of the network entities