PDCP Version Change Security Key Reset

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication systems, particularly in LTE and NR technologies, face challenges in ensuring secure packet data convergence protocol (PDCP) version changes during intra-cell handovers, which can compromise security by allowing multiple communications to use the same security inputs, thereby increasing the risk of unauthorized access.

Innovation Solution

Implementing a method where user equipment (UE) and base stations generate new security keys and reset sequence numbers during a PDCP version change from E-UTRA to NR, ensuring that different security keys are used for communications after the intra-cell handover, thereby preventing the reuse of security inputs across multiple communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If PDCP version change is performed during intra-cell handover without resetting security keys, then communication continuity is maintained, but security is compromised due to reuse of security inputs

Engineering Contradiction:
ImprovesecurityVSAvoidsecurity key management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the security key parameter during PDCP version transition. When transitioning from E-UTRA PDCP to NR PDCP, the system resets the security key to a new value derived from fresh inputs (new gNB ID, new PDCP counter), ensuring that the security parameter changes with the protocol version to prevent reuse vulnerabilities

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent performs preliminary security key reset action before or during the PDCP version change. The security key is reset to a new value based on new inputs before the actual data transmission with the new PDCP version begins, preventing any potential reuse of old security inputs

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security keys are reset during PDCP version change, then security is enhanced by preventing reuse of security inputs, but additional signaling and processing overhead is introduced

Engineering Contradiction:
ImprovesecurityVSAvoidhandover time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges the security key reset operation with the PDCP version change operation. Instead of treating them as separate procedures, the security key reset is integrated into the handover signaling message that already triggers the PDCP version change, so both actions occur simultaneously without adding extra time

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system performs self-service by automatically deriving new security keys from available inputs (new gNB ID, new PDCP counter) without requiring additional external authentication or key distribution messages. The security key generation is self-contained within the handover procedure

Inventive Principle:
Principle #25Self-service

3Device complexity

If the same security inputs are reused across multiple communications, then device complexity is reduced, but security vulnerability increases due to potential unauthorized access

Engineering Contradiction:
Improvesecurity key managementVSAvoidunauthorized access risk
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by proactively resetting security keys to prevent potential unauthorized access. Before any potential security vulnerability can arise from input reuse, the system preemptively generates new security keys with fresh inputs, countering the harmful effect before it can manifest

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent continuously changes security key parameters whenever PDCP version changes occur. By linking security key validity to protocol version transitions, the system ensures that security parameters are dynamically updated, preventing long-term reuse of the same security inputs

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3777275B1Secure packet data convergence protocol (PDCP) version change
Publication Date: 2023.01.11 QUALCOMM INC
  • EP3777275B1 patent drawingFigure 1
  • EP3777275B1 patent drawingFigure 2
  • EP3777275B1 patent drawingFigure 3

AI summary

Various aspects of the present disclosure generally relate to wireless communication. In some aspects, a user equipment (UE) may receive a message that indicates a change from an evolved universal mobile telecommunications system (UMTS) terrestrial radio access (EUTRA) packet data convergence protocol (PDCP) to a New Radio (NR) PDCP, wherein the message includes an instruction to perform an intra-cell handover; generate one or more security keys based at least in part on receiving the message that includes the instruction to perform the intra-cell handover; and communicate using the one or more security keys after the intra-cell handover is performed. Numerous other aspects are provided.