Mobile Network Security Key Generation via NAS Count

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures in mobile communication networks are inadequate during handover procedures, as they often reuse legacy security keys, potentially compromising network integrity and allowing interception of communications.

Innovation Solution

A method and network element that generate a unique security key for each handover using a Non-access Stratum (NAS) count, which is incremented with each handover attempt, ensuring different key values are used, and includes features to manage signaling and retry handover attempts to maintain security context integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If legacy security keys are reused during handover procedures, then device complexity is reduced, but network security is compromised

Engineering Contradiction:
Improvenetwork securityVSAvoidsecurity key management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the parameter used for security key generation from static legacy keys to dynamic parameters including NAS count and handover-specific identifiers. This ensures that security keys are regenerated for each handover procedure, preventing key reuse attacks while maintaining manageable complexity through standardized parameter changes.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces dynamic security key generation where keys change based on handover events and NAS message counts. The security context is updated dynamically during handover procedures rather than remaining static, ensuring that each handover uses fresh cryptographic material while the system adapts to changing network conditions.

Inventive Principle:
Principle #15Dynamics

2Reliability

If security keys are regenerated for each handover, then network security is improved, but signaling overhead increases

Engineering Contradiction:
Improvesecurity context integrityVSAvoidsignaling overhead
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent performs preliminary security context setup during the handover preparation phase, where the target base station receives necessary security parameters from the source base station before the actual handover executes. This preliminary action ensures security keys are ready when needed without requiring additional signaling during the critical handover execution phase.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent merges security context transfer with existing handover signaling messages. Security parameters are embedded within standard handover request and response messages rather than using separate dedicated signaling, thereby reducing overall signaling overhead while ensuring secure key distribution during handover procedures.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If NAS count is incremented for each handover, then key uniqueness is ensured, but synchronization issues may arise

Engineering Contradiction:
Improvekey uniquenessVSAvoidNAS count synchronization
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The patent implements feedback mechanisms where base stations exchange NAS count information during handover procedures. The target base station receives the current NAS count from the source base station and uses it to generate appropriate security keys, ensuring both parties remain synchronized without requiring explicit count increment signaling.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent uses the handover signaling messages as intermediaries to transfer NAS count information between base stations. Rather than directly incrementing and communicating count values, the NAS count is embedded within standard handover messages, allowing indirect but reliable synchronization through the existing signaling infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2465278B1Method of providing telecommunications network security
Publication Date: 2017.04.05 LENOVO INNOVATIONS LTD (HONG KONG)
  • EP2465278B1 patent drawing
  • EP2465278B1 patent drawing
  • EP2465278B1 patent drawing

AI summary

The invention provides for a method of providing network security within a mobile radio communications network and including creating a security context for communications between a mobile radio communications device and the network, the security context being created responsive to an input parameter such as the downlink NAS count, and the method further comprising, as part of each initial handover attempt, controlling the parameter so as to apply a version of the parameter different from a previous version, for example as incremented downlink NAS count, and preferably independently of network signaling messages.