NAS Handover Seed Key Protection in Wireless Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless communication systems face security challenges during handovers, as existing security protocols rely on keys that can be compromised by base stations, potentially leading to unauthorized access and data breaches.
Innovation Solution
A method is introduced where a random handover seed key is protected by a secure protocol, preventing it from being learned by base stations, and is used to derive encryption keys for secure communication between user equipment and target base stations, ensuring secure key management and handovers through the use of a non-access stratum (NAS) protocol.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional security protocols use keys that can be shared with base stations for handover, then handover operation is simplified, but security is compromised as base stations can learn and use the keys for unauthorized access
Solution Approach 1:
The patent introduces a non-access stratum (NAS) protocol as an intermediary layer between the user equipment and the base station. This NAS protocol handles key management and handover signaling separately from the access stratum, preventing base stations from directly accessing or learning the security keys while maintaining smooth handover operation through standardized NAS message exchange.
Solution Approach 2:
The patent segments the security protocol into two distinct layers: access stratum (for radio communication) and non-access stratum (for key management). By separating key management functions into the NAS layer, the system prevents base stations from compromising security keys while maintaining operational simplicity in the access layer for handover procedures.
2Device complexity
If base stations are given access to security keys for handover coordination, then handover coordination is simplified, but the risk of key compromise and data breaches increases
Solution Approach 1:
The NAS protocol serves as a mediator that coordinates handover between base stations without requiring them to share security keys directly. The NAS layer manages the key exchange and handover signaling, eliminating the harmful factor of key compromise while maintaining coordinated handover operation through standardized messaging protocols.
Solution Approach 2:
The patent extracts the security key management function from the base station's access stratum operations and places it in the NAS layer. This extraction removes the harmful dependency where base stations would need to store and manage security keys, thereby eliminating the risk of key compromise while preserving handover coordination capability.
3Reliability
If a secure protocol prevents base stations from learning the handover seed key, then security is improved, but the complexity of key management increases
Solution Approach 1:
The NAS protocol provides universal key management functionality that works across all handover scenarios. By implementing standardized NAS messages for key exchange and protection, the system achieves strong security without increasing practical complexity, as the same NAS protocol handles all key management operations uniformly.
Solution Approach 2:
The patent changes the parameter of key management from base station-level to network-level by using NAS protocols. This parameter change maintains security by preventing base station access to keys while simplifying implementation through standardized NAS message formats and existing network infrastructure for key exchange.
Data Source
AI summary
Example embodiments provide a method for performing handovers and key management while performing handovers. The method includes communicating a random handover seed key protected by a secure protocol from a core component of a network to a user equipment. The secure protocol prevents the random handover seed key from being learned by base stations supported by the core component of the network. The secure protocol may be non-access stratum signaling of an evolved packet system environment for wireless communications.


