Proxy Algorithm Identity Selection for Small Cell Handover Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In communication networks, especially with small cell deployments, there is a challenge in handling security operations when the security capability of User Equipment (UE) is stored in a macro network node instead of the small cell, as the small cell needs to select a security algorithm ID for communications without knowing the UE's security capability, leading to security concerns and increased signaling overhead.
Innovation Solution
A method where a macro network node selects a security algorithm ID on behalf of a small cell based on the UE's security information and a list of security algorithm IDs for the small cell, generating security keys and providing them to the small cell, thus enabling secure communications without the need for the small cell to know the UE's security capability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the small cell stores UE security information locally, then security algorithm ID selection can be performed independently, but security concerns arise from operators regarding centralized security information storage
Solution Approach 1:
The macro eNB acts as an intermediary that holds UE security capability information and provides it to small cells when needed. This mediator approach allows small cells to perform security operations without storing sensitive UE security information locally, thereby maintaining security operation capability while addressing operator security concerns about centralized information storage.
2Object-affected harmful factors
If the small cell does not store UE security information, then security concerns are addressed, but the small cell cannot independently select security algorithm IDs
Solution Approach 1:
The macro eNB is designed with multi-functionality, serving both as the primary access point for UEs and as a security information repository for multiple small cells. When a UE hands over to a small cell, the macro eNB provides the necessary security capability information, enabling the small cell to independently select appropriate security algorithm IDs without storing sensitive UE security information.
3Reliability
If MME is involved in security capability verification during handovers, then security verification is thorough, but signaling overhead increases
Solution Approach 1:
The security verification function is segmented between the macro eNB and small cells. The macro eNB performs the actual security capability verification using stored UE security information and generates security algorithm ID selections. Small cells receive pre-configured security parameters from the macro eNB and can independently verify security capabilities without MME involvement, thereby maintaining thorough security verification while reducing signaling overhead.
Data Source
AI summary
A method for proxy algorithm identity selection may comprise: selecting, at a first network node, a security algorithm identity for a user equipment which is determined to handover to a second network node, based at least in part on security information of the user equipment and a list of security algorithm identities for the second network node; generating security keys for a communication between the user equipment and the second network node, based at least in part on the selected security algorithm identity; providing the security keys and the selected security algorithm identity to the second network node from the first network node; and sending the selected security algorithm identity to the user equipment from the first network node, in response to a handover acknowledgement from the second network node.


