PDCP Version Change Security Key Reset
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless communication systems, particularly in LTE and NR technologies, face challenges in ensuring secure packet data convergence protocol (PDCP) version changes during intra-cell handovers, which can compromise security by allowing multiple communications to use the same security inputs, thereby increasing the risk of unauthorized access.
Innovation Solution
Implementing a method where user equipment (UE) and base stations generate new security keys and reset sequence numbers during a PDCP version change from E-UTRA to NR, ensuring that different security keys are used for communications after the intra-cell handover, thereby preventing the reuse of security inputs across multiple communications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If PDCP version change is performed during intra-cell handover without resetting security keys, then communication continuity is maintained, but security is compromised due to reuse of security inputs
Solution Approach 1:
The patent changes the security key parameter during PDCP version transition. When transitioning from E-UTRA PDCP to NR PDCP, the system resets the security key to a new value derived from fresh inputs (new gNB ID, new PDCP counter), ensuring that the security parameter changes with the protocol version to prevent reuse vulnerabilities
Solution Approach 2:
The patent performs preliminary security key reset action before or during the PDCP version change. The security key is reset to a new value based on new inputs before the actual data transmission with the new PDCP version begins, preventing any potential reuse of old security inputs
2Reliability
If security keys are reset during PDCP version change, then security is enhanced by preventing reuse of security inputs, but additional signaling and processing overhead is introduced
Solution Approach 1:
The patent merges the security key reset operation with the PDCP version change operation. Instead of treating them as separate procedures, the security key reset is integrated into the handover signaling message that already triggers the PDCP version change, so both actions occur simultaneously without adding extra time
Solution Approach 2:
The system performs self-service by automatically deriving new security keys from available inputs (new gNB ID, new PDCP counter) without requiring additional external authentication or key distribution messages. The security key generation is self-contained within the handover procedure
3Device complexity
If the same security inputs are reused across multiple communications, then device complexity is reduced, but security vulnerability increases due to potential unauthorized access
Solution Approach 1:
The patent applies preliminary anti-action by proactively resetting security keys to prevent potential unauthorized access. Before any potential security vulnerability can arise from input reuse, the system preemptively generates new security keys with fresh inputs, countering the harmful effect before it can manifest
Solution Approach 2:
The patent continuously changes security key parameters whenever PDCP version changes occur. By linking security key validity to protocol version transitions, the system ensures that security parameters are dynamically updated, preventing long-term reuse of the same security inputs
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Various aspects of the present disclosure generally relate to wireless communication. In some aspects, a user equipment (UE) may receive a message that indicates a change from an evolved universal mobile telecommunications system (UMTS) terrestrial radio access (EUTRA) packet data convergence protocol (PDCP) to a New Radio (NR) PDCP, wherein the message includes an instruction to perform an intra-cell handover; generate one or more security keys based at least in part on receiving the message that includes the instruction to perform the intra-cell handover; and communicate using the one or more security keys after the intra-cell handover is performed. Numerous other aspects are provided.