Network Switching Node Security Key Generation for Seamless Handover

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network handover processes in communication networks, particularly between 3G, HSPA, and LTE networks, face challenges in maintaining seamless security processing due to the lack of discrimination capability in network switching nodes regarding the target network type.

Innovation Solution

A method where a network switching node generates a target key based on a random value and local keys, sending security information to the target network node, and subsequently sends a handover command to the mobile terminal, allowing secure access to either an HSPA or LTE network without needing to know the target network type.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the MSC server performs different security processing for different target systems (LTE or HSPA), then network security is improved, but the device complexity increases due to the need for discrimination capability

Engineering Contradiction:
Improvenetwork securityVSAvoiddiscrimination capability
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by making the security processing method in the MSC server applicable to both LTE and HSPA target networks without requiring separate processing paths. The MSC server uses a unified security key derivation mechanism that works regardless of the target network type, eliminating the need for discrimination capability while maintaining security for both network types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the parameter of security key derivation by introducing a new approach where the security key is derived based on the target cell ID rather than requiring different processing for different network types. This parameter change allows the same security processing logic to be applied universally across different target networks.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If the MSC server implements discrimination capability to determine target system type, then security processing accuracy is improved, but the ease of operation deteriorates due to increased system complexity

Engineering Contradiction:
Improvesecurity processing accuracyVSAvoidsystem operation
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent extracts the discrimination function from the MSC server by using the target cell ID as the basis for security key derivation. Instead of requiring the MSC server to determine whether the target network is LTE or HSPA, the solution extracts only the necessary information (target cell ID) to perform security processing, simplifying the operation while maintaining accuracy.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If existing network switching nodes are modified to support seamless handover security processing, then handover reliability is improved, but the loss of substance increases due to additional equipment requirements

Engineering Contradiction:
Improvehandover reliabilityVSAvoidequipment cost
Core Design Contradiction:
ReliabilityVSLoss of substance

Solution Approach 1:

The patent applies self-service by enabling the existing MSC server to perform security processing for handover to both LTE and HSPA networks using its existing capabilities and the target cell ID information. No additional equipment or modifications are required, as the MSC server serves itself by deriving security keys based on the target cell ID without needing external assistance or upgrades.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2835998B1Secure processing method and system during network switching
Publication Date: 2019.04.17 HUAWEI TECH CO LTD
  • EP2835998B1 patent drawingFigure 1~2
  • EP2835998B1 patent drawingFigure 3~5
  • EP2835998B1 patent drawingFigure 6~7

AI summary

Embodiments of the present invention disclose a security processing method and system in a network handover process. The method includes: generating, by a network switching node, a target key after receiving a handover request; sending, by the network switching node, security information including the target key to a target network node, and receiving a handover response message sent by the target network node; and sending, by the network switching node, a handover command to a mobile terminal, so that the mobile terminal accesses a target network. By adopting the present invention, security processing in handover of a mobile terminal from a 3G network to an HSPA network or an LTE network may be completed in a case that the network switching node currently used in the network is not changed.