MAC Layer Key Management for Secure Network Handovers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing telecommunications systems lack effective security measures for the Medium Access Control (MAC) layer during handovers, leaving them vulnerable to attacks and compromising the integrity and confidentiality of data transmission.

Innovation Solution

Implementing encryption and integrity protection mechanisms specifically for the MAC layer during handovers, including the activation, deactivation, or continuation of MAC layer security based on handover commands, using dedicated keys and algorithms to ensure secure communication between user equipment and network entities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MAC layer security is implemented during handovers, then the integrity and confidentiality of data transmission is improved, but the device complexity increases

Engineering Contradiction:
Improveintegrity and confidentiality of data transmissionVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security implementation by layer, applying MAC layer security separately from existing PDCP layer security. This allows the MAC layer to have dedicated encryption and integrity protection mechanisms without interfering with the upper PDCP layer, thereby improving reliability while managing complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary key derivation and security context setup before the actual handover occurs. The target gNodeB derives the KgNB* key and prepares security parameters in advance, so that when handover is executed, security is already in place and no additional complexity is introduced during the critical handover transition.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If MAC layer encryption and integrity protection are activated during handovers, then the security against attacks is improved, but the loss of time during handover increases

Engineering Contradiction:
Improvesecurity against attacksVSAvoidhandover time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The target gNodeB performs key derivation (KgNB* from KgNB), algorithm selection, and security context preparation before receiving the handover execution command. This preliminary action ensures that when the handover actually occurs, the MAC layer security mechanisms are already ready and can be activated immediately without adding delay.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent maintains continuous security operation by keeping the MAC layer encryption and integrity protection active throughout the handover process. Rather than establishing security after handover, the security mechanisms operate continuously, ensuring that data transmission remains protected while avoiding interruptions or delays.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If MAC layer security keys are refreshed during handovers, then the security reliability is improved, but the device complexity and processing overhead increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the key management process by maintaining separate MAC layer keys (KgNB*) independent from the PDCP layer keys. This segmentation allows the MAC layer to perform key refresh operations without affecting the PDCP layer security context, improving security reliability while containing processing overhead to a specific layer.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements key refresh through parameter changes in the handover command, specifically introducing the KgNB* key and associated security parameters. By changing the key parameters in a controlled manner during handover, the system achieves secure key refresh without requiring complex reconfiguration of the entire security framework.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250287269A1Medium access control layer security in handovers
Publication Date: 2025.09.11 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20250287269A1 patent drawing
  • US20250287269A1 patent drawing
  • US20250287269A1 patent drawing

AI summary

A user equipment (UE) receives a handover command for a handover of the UE from a source network entity to a target network entity, and in response to the handover command, performing one or more actions related to Medium Access Control (MAC) layer security for communication between the UE and the target network entity.