Mapped Security Context for Wireless Key Consistency
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In wireless communication systems, particularly in LTE and UMTS networks, security context transitions during handovers and RRC connection re-establishments often result in data/signaling ciphering/integrity protection errors due to incompatible keys and missing algorithm indications, leading to transmission failures.
Innovation Solution
A method and device for handling security configuration in wireless communication systems, where the user equipment (UE) uses the mapped security context to derive ciphering and integrity keys, and follows specific procedures to handle key updates and algorithm indications, ensuring consistent key usage across system transitions, and handles missing algorithm indications to maintain secure data and signaling transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the UE updates the K eNB key based on the latest available K ASME key during intra-LTE handover, then security continuity is maintained, but key inconsistency occurs when the current K eNB is associated with a different K ASME
Solution Approach 1:
The patent implements a feedback mechanism where the keyChangeIndicator IE provides information about whether a key update should occur. The UE uses this feedback to determine whether to update the K eNB key based on the latest K ASME or maintain association with the current K ASME, thereby resolving the contradiction between security continuity and key consistency.
Solution Approach 2:
The patent introduces dynamic key management where the UE can switch between different key update modes based on the keyChangeIndicator. This dynamic approach allows the system to adapt to different scenarios: updating to the latest K ASME when keyChangeIndicator is TRUE, or maintaining current K ASME association when it is FALSE, thus resolving the static contradiction.
2Adaptability or versatility
If the UE uses mapped security context to derive EPS keys during inter-system handover, then handover from UMTS to LTE is enabled, but key derivation conflicts arise with cached security context
Solution Approach 1:
The patent applies preliminary action by pre-establishing both cached security context (from LTE AKA) and mapped security context (from UMTS AKA) before handover. The keyChangeIndicator IE is prepared in advance to guide the UE on which context to use, preventing key derivation conflicts during the actual handover execution.
Solution Approach 2:
The keyChangeIndicator IE acts as an intermediary that mediates between cached and mapped security contexts. It provides the necessary information to the UE to select the appropriate key derivation path, enabling seamless inter-system handover while maintaining key derivation consistency with the network.
3Reliability
If the keyChangeIndicator IE is set to TRUE to update K eNB based on latest K ASME, then security freshness is improved, but compatibility with current K eNB association is lost
Solution Approach 1:
The patent makes the key update mechanism dynamic through the keyChangeIndicator IE. When set to TRUE, the system prioritizes security freshness by updating to the latest K ASME. When set to FALSE, it maintains compatibility with the current K eNB association. This dynamic switching resolves the contradiction between security freshness and compatibility.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method of handling security configuration for a mobile device using a mapped security context in a wireless communication system (10) includes utilizing the mapped security context to derive ciphering and integrity keys when security configuration, indicating a key update based on a cached security context, is received (410).