NAS Handover Seed Key Protection in Wireless Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication systems face security challenges during handovers, as existing security protocols rely on keys that can be compromised by base stations, potentially leading to unauthorized access and data breaches.

Innovation Solution

A method is introduced where a random handover seed key is protected by a secure protocol, preventing it from being learned by base stations, and is used to derive encryption keys for secure communication between user equipment and target base stations, ensuring secure key management and handovers through the use of a non-access stratum (NAS) protocol.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional security protocols use keys that can be shared with base stations for handover, then handover operation is simplified, but security is compromised as base stations can learn and use the keys for unauthorized access

Engineering Contradiction:
Improvehandover operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a non-access stratum (NAS) protocol as an intermediary layer between the user equipment and the base station. This NAS protocol handles key management and handover signaling separately from the access stratum, preventing base stations from directly accessing or learning the security keys while maintaining smooth handover operation through standardized NAS message exchange.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the security protocol into two distinct layers: access stratum (for radio communication) and non-access stratum (for key management). By separating key management functions into the NAS layer, the system prevents base stations from compromising security keys while maintaining operational simplicity in the access layer for handover procedures.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If base stations are given access to security keys for handover coordination, then handover coordination is simplified, but the risk of key compromise and data breaches increases

Engineering Contradiction:
Improvehandover coordinationVSAvoidkey compromise risk
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The NAS protocol serves as a mediator that coordinates handover between base stations without requiring them to share security keys directly. The NAS layer manages the key exchange and handover signaling, eliminating the harmful factor of key compromise while maintaining coordinated handover operation through standardized messaging protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the security key management function from the base station's access stratum operations and places it in the NAS layer. This extraction removes the harmful dependency where base stations would need to store and manage security keys, thereby eliminating the risk of key compromise while preserving handover coordination capability.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If a secure protocol prevents base stations from learning the handover seed key, then security is improved, but the complexity of key management increases

Engineering Contradiction:
ImprovesecurityVSAvoidkey management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The NAS protocol provides universal key management functionality that works across all handover scenarios. By implementing standardized NAS messages for key exchange and protection, the system achieves strong security without increasing practical complexity, as the same NAS protocol handles all key management operations uniformly.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the parameter of key management from base station-level to network-level by using NAS protocols. This parameter change maintains security by preventing base station access to keys while simplifying implementation through standardized NAS message formats and existing network infrastructure for key exchange.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8179860B2Systems and method for performing handovers, or key management while performing handovers in a wireless communication system
Publication Date: 2012.05.15 NOKIA TECHNOLOGIES OY
  • US8179860B2 patent drawing
  • US8179860B2 patent drawing
  • US8179860B2 patent drawing

AI summary

Example embodiments provide a method for performing handovers and key management while performing handovers. The method includes communicating a random handover seed key protected by a secure protocol from a core component of a network to a user equipment. The secure protocol prevents the random handover seed key from being learned by base stations supported by the core component of the network. The secure protocol may be non-access stratum signaling of an evolved packet system environment for wireless communications.