MAC Layer Key Management for Secure Network Handovers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing telecommunications systems lack effective security measures for the Medium Access Control (MAC) layer during handovers, leaving them vulnerable to attacks and compromising the integrity and confidentiality of data transmission.
Innovation Solution
Implementing encryption and integrity protection mechanisms specifically for the MAC layer during handovers, including the activation, deactivation, or continuation of MAC layer security based on handover commands, using dedicated keys and algorithms to ensure secure communication between user equipment and network entities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MAC layer security is implemented during handovers, then the integrity and confidentiality of data transmission is improved, but the device complexity increases
Solution Approach 1:
The patent segments the security implementation by layer, applying MAC layer security separately from existing PDCP layer security. This allows the MAC layer to have dedicated encryption and integrity protection mechanisms without interfering with the upper PDCP layer, thereby improving reliability while managing complexity through modular architecture.
Solution Approach 2:
The patent implements preliminary key derivation and security context setup before the actual handover occurs. The target gNodeB derives the KgNB* key and prepares security parameters in advance, so that when handover is executed, security is already in place and no additional complexity is introduced during the critical handover transition.
2Reliability
If MAC layer encryption and integrity protection are activated during handovers, then the security against attacks is improved, but the loss of time during handover increases
Solution Approach 1:
The target gNodeB performs key derivation (KgNB* from KgNB), algorithm selection, and security context preparation before receiving the handover execution command. This preliminary action ensures that when the handover actually occurs, the MAC layer security mechanisms are already ready and can be activated immediately without adding delay.
Solution Approach 2:
The patent maintains continuous security operation by keeping the MAC layer encryption and integrity protection active throughout the handover process. Rather than establishing security after handover, the security mechanisms operate continuously, ensuring that data transmission remains protected while avoiding interruptions or delays.
3Reliability
If MAC layer security keys are refreshed during handovers, then the security reliability is improved, but the device complexity and processing overhead increase
Solution Approach 1:
The patent segments the key management process by maintaining separate MAC layer keys (KgNB*) independent from the PDCP layer keys. This segmentation allows the MAC layer to perform key refresh operations without affecting the PDCP layer security context, improving security reliability while containing processing overhead to a specific layer.
Solution Approach 2:
The patent implements key refresh through parameter changes in the handover command, specifically introducing the KgNB* key and associated security parameters. By changing the key parameters in a controlled manner during handover, the system achieves secure key refresh without requiring complex reconfiguration of the entire security framework.
Data Source
AI summary
A user equipment (UE) receives a handover command for a handover of the UE from a source network entity to a target network entity, and in response to the handover command, performing one or more actions related to Medium Access Control (MAC) layer security for communication between the UE and the target network entity.


