Key Derivation for Handover Security in LTE

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing handover techniques in wireless communication systems, such as those used in LTE/UTRAN, face security vulnerabilities due to the repetition of keystreams during processes like handover and NAS service requests, which can lead to security breaches.

Innovation Solution

A method is introduced to derive different key values for handover from a GERAN/UTRAN system to an E-UTRAN system using distinct input values for the key derivation function, ensuring that the same key is not reused across different processes, thereby preventing keystream repetition.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If the same key derivation function and input values are used for both handover and NAS service request processes, then the key derivation process is simple and efficient, but keystream repetition occurs leading to security vulnerabilities

Engineering Contradiction:
Improvesimplicity of key derivation processVSAvoidsecurity against keystream repetition
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent applies local quality by using different input values (S1 for handover, S2 for NAS service request) in the key derivation function for different processes. This ensures that while the overall key derivation mechanism remains consistent, each specific process receives customized input parameters, preventing keystream repetition and improving security without fundamentally changing the derivation approach.

Inventive Principle:
Principle #3Local quality

2Reliability

If different input values are used for handover and NAS service request key derivation, then keystream repetition is prevented improving security, but the complexity of key management increases

Engineering Contradiction:
Improvesecurity against keystream repetitionVSAvoidcomplexity of key management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by using a single key derivation function KDF that handles both handover and NAS service request processes. The function remains universal and multi-functional, accepting different input values (S1 or S2) based on the process type. This approach prevents keystream repetition through varied inputs while maintaining a unified, simple key derivation framework that does not increase overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If the UL NAS COUNT value is used as input to KDF for handover, then the same key is derived for both handover and subsequent NAS requests, but this causes security breaches due to keystream repeat

Engineering Contradiction:
Improveefficiency of key derivationVSAvoidsecurity breach risk from keystream repeat
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies segmentation by dividing the input string S into distinct components: S1 for handover processes and S2 for NAS service request processes. Each segment (S1 or S2) contains specific parameters relevant to its process type (e.g., handover indicator, NAS COUNT). This segmentation ensures that different processes use different input segments, preventing keystream repetition and eliminating security breaches while maintaining efficient key derivation.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2446653B1Key derivation to facilitate handover security
Publication Date: 2018.07.18 QUALCOMM INC
  • EP2446653B1 patent drawingFigure 1
  • EP2446653B1 patent drawingFigure 2
  • EP2446653B1 patent drawingFigure 3

AI summary

Systems, methods and apparatus for facilitating handover security are provided. In some embodiments, the method can include deriving a key value for handover from a GERAN/UTRAN system to an E-UTRAN system using a first input value. The method can also include deriving a key value for a connection establishment using a second input value, wherein the first input value is different from the second input value and is different from input values derived subsequent to the second input value, and wherein the first input value, the second input value and the input values derived subsequent to the second input value are configured to be input to a same key derivation function configured to output a key for use between a network entity and user equipment.