Radio Access Network Security Algorithm Handover Switching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current telecommunications networks using a single security algorithm for Radio Access Networks are inefficient and insecure during handover processes, as negotiations are unsecured and inefficient, potentially leaving communication vulnerable if one algorithm is compromised.

Innovation Solution

A method and apparatus for securely changing the security algorithm during handover by sending handover indication and security requirement messages between access points and mobile stations, ensuring secure communication by switching to a secondary algorithm, which is secured using a data-processing device controlled by a computer program.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single security algorithm is used in the Radio Access Network, then device complexity is reduced and ease of operation is improved, but network security deteriorates because the system becomes vulnerable if that single algorithm is compromised

Engineering Contradiction:
Improvenetwork securityVSAvoidsecurity algorithm complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements multiple security algorithms (first security algorithm and second security algorithm) within the same Radio Access Network system, allowing the network to perform security functions using different algorithms depending on the communication phase. The system can universally handle both algorithms without requiring separate systems, thereby improving security while maintaining reasonable complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent dynamically switches between security algorithms based on the communication phase. During initial access and handover, the first security algorithm is used, while during normal communication, the second security algorithm is employed. This dynamic adaptation allows the system to optimize security posture without permanently increasing complexity.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If security algorithm negotiations are performed between mobile station and base station, then adaptability is improved by allowing algorithm selection, but efficiency deteriorates due to additional message exchanges and time consumption

Engineering Contradiction:
Improvesecurity algorithm selectionVSAvoidhandover efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent performs security algorithm negotiation and selection in advance during the handover preparation phase, before the actual handover execution. The target base station determines the appropriate second security algorithm and includes this information in the handover command message sent to the mobile station. This preliminary action eliminates the need for additional negotiation messages during the critical handover execution phase, thereby maintaining handover efficiency while achieving adaptability.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If plaintext messages are exchanged during security algorithm negotiations, then ease of operation is improved by simplifying message format, but security deteriorates because the negotiation process itself becomes vulnerable to eavesdropping

Engineering Contradiction:
Improvemessage exchange simplicityVSAvoidnegotiation security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent performs security algorithm negotiation and establishment before the actual data communication begins. The security parameters are determined and configured in advance during the handover preparation phase, so that when data communication starts, the secure algorithm is already in place. This preliminary security setup ensures that no plaintext security negotiations occur during the vulnerable data transmission phase.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces the handover command message as an intermediary carrier that conveys security algorithm information from the target base station to the mobile station. Instead of exchanging multiple plaintext negotiation messages, the security algorithm selection information is embedded within the structured handover command message, which is itself protected by the first security algorithm, thereby securing the negotiation process while maintaining operational simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2127463B1Changing radio access network security algorithm during handover
Publication Date: 2021.05.12 NOKIA TECHNOLOGIES OY
  • EP2127463B1 patent drawingFigure 1a
  • EP2127463B1 patent drawingFigure 1b
  • EP2127463B1 patent drawingFigure 2

AI summary

The invention allows changing a Radio Access Network security algorithm during handover in a manner that is efficient and secure. A security message is received at a mobile station previously using a first security algorithm in communication with a first access point, which message instructs to use a second security algorithm required by a second access point. In response, the mobile stationis changed to use the second security algorithm.