Radio Access Network Security Algorithm Handover Switching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current telecommunications networks using a single security algorithm for Radio Access Networks are inefficient and insecure during handover processes, as negotiations are unsecured and inefficient, potentially leaving communication vulnerable if one algorithm is compromised.
Innovation Solution
A method and apparatus for securely changing the security algorithm during handover by sending handover indication and security requirement messages between access points and mobile stations, ensuring secure communication by switching to a secondary algorithm, which is secured using a data-processing device controlled by a computer program.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single security algorithm is used in the Radio Access Network, then device complexity is reduced and ease of operation is improved, but network security deteriorates because the system becomes vulnerable if that single algorithm is compromised
Solution Approach 1:
The patent implements multiple security algorithms (first security algorithm and second security algorithm) within the same Radio Access Network system, allowing the network to perform security functions using different algorithms depending on the communication phase. The system can universally handle both algorithms without requiring separate systems, thereby improving security while maintaining reasonable complexity.
Solution Approach 2:
The patent dynamically switches between security algorithms based on the communication phase. During initial access and handover, the first security algorithm is used, while during normal communication, the second security algorithm is employed. This dynamic adaptation allows the system to optimize security posture without permanently increasing complexity.
2Adaptability or versatility
If security algorithm negotiations are performed between mobile station and base station, then adaptability is improved by allowing algorithm selection, but efficiency deteriorates due to additional message exchanges and time consumption
Solution Approach 1:
The patent performs security algorithm negotiation and selection in advance during the handover preparation phase, before the actual handover execution. The target base station determines the appropriate second security algorithm and includes this information in the handover command message sent to the mobile station. This preliminary action eliminates the need for additional negotiation messages during the critical handover execution phase, thereby maintaining handover efficiency while achieving adaptability.
3Ease of operation
If plaintext messages are exchanged during security algorithm negotiations, then ease of operation is improved by simplifying message format, but security deteriorates because the negotiation process itself becomes vulnerable to eavesdropping
Solution Approach 1:
The patent performs security algorithm negotiation and establishment before the actual data communication begins. The security parameters are determined and configured in advance during the handover preparation phase, so that when data communication starts, the secure algorithm is already in place. This preliminary security setup ensures that no plaintext security negotiations occur during the vulnerable data transmission phase.
Solution Approach 2:
The patent introduces the handover command message as an intermediary carrier that conveys security algorithm information from the target base station to the mobile station. Instead of exchanging multiple plaintext negotiation messages, the security algorithm selection information is embedded within the structured handover command message, which is itself protected by the first security algorithm, thereby securing the negotiation process while maintaining operational simplicity.
Data Source
Figure 1a
Figure 1b
Figure 2
AI summary
The invention allows changing a Radio Access Network security algorithm during handover in a manner that is efficient and secure. A security message is received at a mobile station previously using a first security algorithm in communication with a first access point, which message instructs to use a second security algorithm required by a second access point. In response, the mobile stationis changed to use the second security algorithm.