PDCP Security Key Generation for Dual Connectivity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G wireless communication systems, small cell base stations face security vulnerabilities due to weak management, leading to potential personal information leaks and security issues, especially when dual connectivity is employed, where a terminal connects to both macro and small cell base stations, causing control overhead and latency problems.

Innovation Solution

A method and apparatus for generating and maintaining separate security keys for macro and small cell base stations, allowing independent key management and key exchange during handovers, additions, or releases, using a mobility management entity to minimize control overhead and ensure robust security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If dual connectivity is employed to connect terminal to both macro and small cell base stations, then data transmission rate is improved, but security vulnerability increases due to weak management of small cell base stations

Engineering Contradiction:
Improvedata transmission rateVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the security key management by creating separate security keys for macro cell base stations and small cell base stations. The master key is divided into a first security key for macro cells and a second security key for small cells, allowing independent security management for each cell type while maintaining dual connectivity for high data transmission rates.

Inventive Principle:
Principle #1Segmentation

2Reliability

If separate security keys are generated for macro and small cell base stations, then security management is improved, but control overhead increases

Engineering Contradiction:
Improvesecurity managementVSAvoidcontrol overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary action by pre-generating multiple security keys (first security key for macro cells, second security key for small cells) before handover occurs. The mobility management entity stores these keys in advance, so when handover to a small cell is needed, the terminal can immediately use the pre-prepared second security key without additional key exchange signaling, thus reducing control overhead while maintaining separate security management.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If frequent handovers are supported in small cell networks, then network flexibility is improved, but latency increases due to security key exchange procedures

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidlatency
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-configuring the terminal with the second security key for small cell base stations before handover. When handover occurs, the terminal can immediately establish secure connection without waiting for key exchange procedures, significantly reducing latency and enabling frequent handovers while maintaining network flexibility.

Inventive Principle:
Principle #10Preliminary action

4Productivity

If small cell base stations are deployed to increase network capacity, then network capability is improved, but security maintenance difficulty increases due to scattered indoor locations

Engineering Contradiction:
Improvenetwork capacityVSAvoidsecurity maintenance
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent introduces the mobility management entity as an intermediary that centrally manages security keys for all small cell base stations. Instead of requiring physical access to each scattered small cell for security maintenance, the mobility management entity can remotely manage and update the second security keys for all small cells, making security maintenance easy despite the dispersed locations of small cell base stations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11050727B2Security key generation and management method of PDCP distributed structure for supporting dual connectivity
Publication Date: 2021.06.29 SAMSUNG ELECTRONICS CO LTD
  • US11050727B2 patent drawing
  • US11050727B2 patent drawing
  • US11050727B2 patent drawing

AI summary

The present disclosure relates to a pre-5th-Generation (5G) or 5G communication system to be provided for supporting higher data rates Beyond 4th-Generation (4G) communication system such as Long Term Evolution (LTE). A method for communicating by a user equipment with a macro cell base station and a small cell base station in a communication system is provided. The method comprises applying a first base station security key to a first communication link with the macro cell base station; generating a second base station security key to be used for a second communication link with the small cell base station based on the first base station security key; applying the second base station security key to the second communication link with the small cell base station; and communicating through at least one of the first communication link and the second communication link.