MME Security Key Generation for LTE Handover

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the 3GPP UMTS system, the security key used by the access layer cannot be generated during handovers between different access systems, leading to inadequate protection of signaling and data, posing a safety hazard.

Innovation Solution

A method where the Mobility Management Entity (MME) generates a security key based on the root key KASME and a specific value, such as 0, and transmits it to the target eNB, allowing the user equipment to generate the security key used by the eNB, utilizing a one-way key derivation function to ensure secure handovers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the UE handovers from UTRAN to EUTRAN using the related art method, then the root key KASME of EUTRAN can be generated, but the access layer security key (KeNB) cannot be generated, resulting in inadequate security protection

Engineering Contradiction:
Improvesecurity protectionVSAvoidkey generation process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The MME performs preliminary action by generating the access layer security key (KeNB) in advance based on the root key KASME before the handover is completed. This pre-generated key is then included in the handover request message to the target eNB, ensuring that security protection is established before the actual handover occurs, thus resolving the issue of inadequate security protection during handover.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The MME acts as an intermediary by deriving the access layer security key from the root key KASME using a key derivation function. This intermediary process transforms the high-level root key into the specific access layer key needed by the eNB, enabling security protection without requiring the eNB to directly handle the root key generation process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the specific value is forwarded to the MME for security key generation, then the security key can be generated, but the signaling burden increases

Engineering Contradiction:
Improvesecurity key generationVSAvoidsignaling burden
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The MME performs self-service by generating the access layer security key using only the root key KASME that it already possesses from previous authentication procedures. The MME does not need to request or receive additional specific values from the UE or other entities, thereby eliminating extra signaling and reducing the signaling burden while still achieving secure key generation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8452007B2Security key generating method, device and system
Publication Date: 2013.05.28 ZTE CORP
  • US8452007B2 patent drawing
  • US8452007B2 patent drawing
  • US8452007B2 patent drawing

AI summary

A security key generating method, device and system are provided, wherein, the method is used for generating a security key in the process of the handover to an EUTRAN network from other network, the method includes: an MME generates a security key based on a root key KASME of the EUTRAN network, a specific value and/or other parameters and transmits a handover request message carrying the security key to a target evolved Node B, i.e. eNB; a UE generates the security key which used by the target eNB based on the root key KASME of the EUTRAN network, the specific value and/or other parameters. The application of the present invention adopts a specific value, KASME and/or other parameters to output a security key, which can solve the problem existed in the related technology, the problem is that the middle security key used by access layer while handover between different access system can not be generated, and then it can not realize the security protection of the access layer. So the application of the present invention makes the signaling and/or data of the access layer be efficiently protected, thereby improving the security of the access layer.