Handover Security Negotiation for LTE Uplink
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for handover between 2G/3G systems and LTE systems fail to ensure secure negotiation of security parameters, as they do not account for the additional security layers in the LTE system, specifically Non-Access Stratum (NAS) and Access Stratum (AS), leading to a lack of secure handover solutions.
Innovation Solution
A method and apparatus that transmit and negotiate security information between the User Equipment (UE) and the LTE system, including NAS and AS security information, using a transparent container to facilitate secure handover by deriving and selecting appropriate encryption and integrity protection algorithms, enabling secure association between the UE and the LTE system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional handover methods are used between 2G/3G and LTE systems, then handover can be completed, but security parameters are not properly negotiated leading to security vulnerabilities
Solution Approach 1:
The patent segments security negotiation into two distinct layers: NAS (Non-Access Stratum) security parameters and AS (Access Stratum) security parameters. This segmentation allows each layer to be negotiated independently with its own security context, ensuring that LTE-specific security requirements are properly addressed without conflating them with legacy 2G/3G security mechanisms.
Solution Approach 2:
The patent performs preliminary security context establishment by deriving NAS security parameters and AS security parameters in advance during the handover preparation phase. The source eNB derives the target eNB's NAS security context and AS security context before the actual handover execution, ensuring security is established beforehand rather than during the critical handover moment.
2Reliability
If additional security layers (NAS and AS) are negotiated in LTE handover, then security is improved, but signaling overhead increases
Solution Approach 1:
The patent merges the negotiation of NAS security parameters and AS security parameters into a unified handover signaling flow. By combining these security negotiations with existing handover messages rather than creating separate dedicated signaling exchanges, the patent reduces overall signaling overhead while still establishing both security layers.
Solution Approach 2:
The patent enables the UE to self-derive security parameters using received security context information. The UE uses the received NAS security context and AS security context along with stored keys to independently derive the necessary security parameters, reducing the need for extensive explicit signaling from the network side.
3Reliability
If security parameters are negotiated during handover from 2G/3G to LTE, then security compatibility is improved, but handover time increases
Solution Approach 1:
The patent performs security context derivation and security parameter preparation in advance during the handover preparation phase at the source eNB. By deriving the target eNB's NAS security context and AS security context before handover execution, the patent eliminates time-consuming security negotiations from the critical handover execution path, thus reducing overall handover time.
Solution Approach 2:
The patent skips detailed security parameter negotiations during the actual handover execution by having already established the security context in advance. The handover signaling directly conveys the pre-prepared security parameters to the UE, allowing the handover to proceed rapidly without pausing for iterative security negotiations.
Data Source
AI summary
A solution for security negotiation during handover of a user equipment (UE) between different radio access technologies is provided. In the solution, the UE receives non-access stratum (NAS) security information and access stratum (AS) security information which are selected by the target system and then performs security negotiation with the target system according to the received NAS security information and AS security information. As such, the UE may obtain the key parameter information of the NAS and AS selected by a Long Term Evolution (LTE) system and perform security negotiation with the LTE system when the UE hands over from a different system, such as a Universal Terrestrial Radio Access Network (UTRAN), to the LTE system.


