Mobile Handover Security via Switching Center Key Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional mobile communication systems face security vulnerabilities during handovers, as the handover source radio base station can generate the security key used between the handover target radio base station and the mobile station, compromising key secrecy.

Innovation Solution

A method where the handover source radio base station transmits a handover request with counter and physical cell identification information to the switching center, which changes the counter and parameter, and then transmits this to the handover target radio base station, allowing the target station to generate a first key using temporary identification information, ensuring the security key remains secret from the source station.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the handover source radio base station generates the security key KeNB using a predetermined rule based on parameter KeNB*, then the handover process can be completed, but the security key KeNB becomes known to the handover source radio base station, creating a security vulnerability

Engineering Contradiction:
Improvesecurity key secrecyVSAvoidkey generation process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a switching center as an intermediary between the handover source radio base station and the handover target radio base station. The switching center receives the parameter KeNB* from the source base station, generates the security key KeNB using a predetermined rule, and then provides this key to the target base station. This intermediary approach ensures that the source base station never knows the generated security key, as it only transmits the parameter KeNB* without the generation capability, thereby resolving the security vulnerability while maintaining manageable process complexity through centralized key management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the handover source radio base station transmits the security key KeNB directly to the handover target radio base station, then the handover process is simplified, but the security key secrecy is compromised

Engineering Contradiction:
Improvehandover process simplicityVSAvoidsecurity key secrecy
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent employs the switching center as a mediator that receives parameter KeNB* from the source base station, generates the security key KeNB, and distributes it to the target base station. This approach maintains operational simplicity by automating the key generation and distribution process through the switching center, while simultaneously ensuring security key secrecy since the source base station only handles the parameter KeNB* and never the generated key itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the security key generation function from the handover source radio base station and relocates it to the switching center. By separating the generation of security key KeNB from the transmission of parameter KeNB*, the system ensures that the source base station only transmits the parameter without possessing the generation capability, thus maintaining both operational simplicity and security key secrecy.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8457638B2Mobile communication method
Publication Date: 2013.06.04 NTT DOCOMO INC
  • US8457638B2 patent drawing
  • US8457638B2 patent drawing
  • US8457638B2 patent drawing

AI summary

In a mobile communication method according to the present invention includes the steps of: transmitting, from a handover source radio base station to a swithcing center, a handover request including an NCC, a PCI and a KeNB*; changing, at the swithcing center, the NCC, changing, at the swithcing center, the KeNB* on the basis of the PCI, and transmitting, from the swithcing center to the handover target radio base station, the handover request including the changed NCC and the changed KeNB*; generating, at the handover target radio base station, a first key on the basis of the KeNB*; and generating, at the mobile station, the first key on the basis of the NCC and the PCI included in a handover command.