LTE WTRU Security Key Management and NAS Message Handling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing LTE security architecture lacks adequate procedures for handling security failures, particularly in the NAS layer, where messages may be received without proper ciphering and/or integrity protection, and key management is not well-defined during transitions between network states.

Innovation Solution

The proposed solution involves defining new procedures for the wireless transmit receive unit (WTRU) to handle security failures by checking the security parameters of NAS messages and taking appropriate actions, such as dropping or re-authenticating messages, and implementing a new key handling mechanism during transitions from EMM_Connected to EMM_Idle mode, including the deletion of security parameters and generation of new keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the LTE security architecture uses three layers of security (NAS security, RRC security, and U-plane security) with separate keys, then security coverage and protection scope are improved, but device complexity and key management difficulty increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments security into three distinct layers (NAS security, RRC security, and U-plane security) with separate key sets (KNASenc, KRRCenc, KUPenc). Each layer has independent key management and security procedures, allowing targeted security measures without compromising other layers. This segmentation resolves the contradiction by providing comprehensive security coverage while maintaining manageable complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension to key management by associating security keys with specific protocol layers and message types. Instead of a single key hierarchy, the system uses multiple key dimensions (NAS layer keys, RRC layer keys, U-plane keys) that can be independently managed and validated, reducing overall system complexity while enhancing security coverage.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If the WTRU checks security parameters of NAS messages and handles security failures by dropping or re-authenticating messages, then security reliability is improved, but processing time and message handling delay increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidmessage handling delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary security parameter checking at the NAS layer before message processing continues. By validating security parameters upfront and handling failures through predefined procedures (dropping or re-authentication), the system avoids time-consuming security checks during later processing stages, thus reducing overall message handling delay while maintaining high security reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent establishes feedback mechanisms where the WTRU monitors security parameter validity and provides feedback to control message handling. When security failures are detected, the system automatically triggers appropriate responses (dropping insecure messages or initiating re-authentication), creating a closed-loop security validation process that minimizes delays through efficient feedback-driven decision-making.

Inventive Principle:
Principle #23Feedback

3Reliability

If the WTRU deletes security parameters and generates new keys during transitions from EMM_Connected to EMM_Idle mode, then security freshness and protection against key compromise are improved, but processing complexity and computational overhead increase

Engineering Contradiction:
Improvesecurity freshnessVSAvoidkey handling complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic key management where security parameters are automatically deleted and new keys are generated during state transitions (EMM_Connected to EMM_Idle). This dynamic approach ensures security freshness by updating keys according to current network conditions, preventing key compromise while managing complexity through automated transition-based key lifecycle management.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes key management parameters based on network state transitions. When transitioning to EMM_Idle mode, the system modifies key validity parameters by deleting old security parameters and generating new ones. This parameter change approach maintains security freshness without requiring complex manual key management, as the transitions are triggered automatically by network state changes.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If the LTE system implements separate NAS security and RRC security with independent key derivation, then security isolation and resistance to key compromise are improved, but authentication complexity and procedure length increase

Engineering Contradiction:
Improvesecurity isolationVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments authentication into separate NAS and RRC phases with independent key derivation. NAS authentication establishes KNASenc keys for signaling protection, while RRC authentication separately establishes KRRCenc keys for radio communication. This segmentation provides security isolation between layers, preventing key compromise in one layer from affecting others, while managing authentication time through parallel processing and efficient key derivation algorithms.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9420468B2Method and apparatus to implement security in a long term evolution wireless device
Publication Date: 2016.08.16 INTERDIGITAL PATENT HOLDINGS INC
  • US9420468B2 patent drawing
  • US9420468B2 patent drawing
  • US9420468B2 patent drawing

AI summary

A wireless transmit receive unit (WTRU) is configured to receive unciphered and ciphered messages. The unciphered messages include identity requests, authentication requests, non-access stratum (NAS) security mode commands and tracking area update responses. The ciphered messages may come from the NAS and a Radio Resource Controller (RRC). The messages are ciphered using security keys.