Radio Bearer Security Key Refresh via Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication systems face challenges in efficiently refreshing security keys for radio bearers without affecting other bearers, particularly in scenarios like COUNT wrap-around, where a single radio bearer's key change can impact others, leading to potential security vulnerabilities and disruptions.
Innovation Solution
The method involves releasing an existing radio bearer and adding a new one with new security keys, allowing for independent key management and refreshment of security keys for a subset of configured radio bearers, ensuring that only the affected bearer's keys are changed without impacting others, using a network entity's indication to initiate the process and configuring the new bearer with new security parameters.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security keys for all radio bearers are refreshed simultaneously, then security vulnerability is reduced, but communication disruption increases
Solution Approach 1:
The patent segments the radio bearers into different groups (first plurality and second plurality) with different security key refresh timings. This allows selective key refresh for specific bearers while maintaining others, thereby improving security without causing complete communication disruption across all bearers.
Solution Approach 2:
The patent implements dynamic key refresh where different radio bearers have different key refresh cycles and timings. The network can dynamically decide which bearers to refresh based on security requirements and communication priorities, balancing security needs with communication continuity.
2Reliability
If security keys are refreshed frequently, then security is improved, but system overhead and complexity increase
Solution Approach 1:
By dividing bearers into groups with different refresh schedules, the system avoids the complexity of managing uniform frequent refreshes across all bearers. Each group can have optimized refresh timing based on its specific security requirements, reducing overall management complexity.
Solution Approach 2:
The patent changes the parameter of key refresh timing from a uniform fixed schedule to a variable schedule based on bearer priority and security requirements. This allows the system to adapt key refresh frequency dynamically, improving security where needed while reducing overhead where not required.
3Reliability
If COUNT wrap-around triggers key refresh for one bearer, then security is maintained, but other bearers may be inadvertently affected
Solution Approach 1:
The patent segments the bearer management such that COUNT wrap-around events in one bearer only trigger key refresh for that specific bearer or its designated group, not all bearers. This segmentation isolates the impact and maintains operational independence among different bearers.
Solution Approach 2:
The patent extracts the key refresh trigger mechanism from a global system-wide operation to a per-bearer or per-group operation. When COUNT wrap-around occurs, only the affected bearer's key is refreshed, separating the security management of individual bearers from the overall system.
Data Source
AI summary
A method and apparatus for refreshing the security keys of a subset of configured radio bearers including less than all of the currently configured radio bearers is provided. An indication is received from a network entity to release one or more radio bearers from the subset of configured radio bearers for which the refresh of security keys is desired. A new radio bearer is added for each of the one or more radio bearers being released. Each of the new radio bearers is added with new security keys.


