Relay Node Security Key Derivation for LTE-A Air Interface Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The introduction of relay nodes in LTE-A systems increases the number of air interface links, leading to a higher key level, which existing security mechanisms are unable to effectively protect, resulting in inadequate security protection for data on each segment of the air interface.

Innovation Solution

A method and device for obtaining a security key in a relay system, where an eNB obtains an initial key from an MME, forwards it to a relay node, and uses this key to locally derive a root key and subsequently an air interface protection key to protect data on the Un interface link, ensuring effective security protection for each active UE.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If relay nodes are introduced to improve network coverage and throughput, then the network coverage and throughput are improved, but the security protection capability deteriorates because existing security mechanisms cannot effectively protect data on each segment of the air interface

Engineering Contradiction:
ImprovethroughputVSAvoidsecurity protection capability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the air interface into multiple links (Uu interface between UE and RN, Un interface between RN and eNB) and assigns different security protection mechanisms to each segment. The UE-RN link uses traditional AS security with dedicated keys, while the RN-eNB link uses a new security mechanism with separate key derivation, ensuring each segment has appropriate security protection independent of the others.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The relay node acts as an intermediary that receives security parameters from both the UE and eNB, performs separate key derivation for each link, and independently applies security protection to data on each air interface segment. This intermediary role allows the system to maintain security while enabling multi-hop communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Area of stationary object

If the number of air interface links is increased by introducing relay nodes, then the network coverage is improved, but the key management complexity increases making existing security mechanisms ineffective

Engineering Contradiction:
Improvenetwork coverage areaVSAvoidkey management complexity
Core Design Contradiction:
Area of stationary objectVSDevice complexity

Solution Approach 1:

The security management is segmented into independent key derivation processes for each air interface link. The eNB derives keys for the Un interface separately from those used for the Uu interface, and the RN performs similar separate derivations. This segmentation prevents the complexity from propagating across the entire system while allowing extended coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each air interface link is assigned its own local security parameters and key derivation process tailored to that specific link's requirements. The eNB and RN each maintain separate security contexts for different interfaces, allowing localized key management that scales with network complexity rather than becoming uniformly complex.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP2487947B1Method and device for acquiring safe key in relay system
Publication Date: 2018.09.12 HUAWEI TECH CO LTD
  • EP2487947B1 patent drawingFigure 1
  • EP2487947B1 patent drawingFigure 2
  • EP2487947B1 patent drawingFigure 3

AI summary

A method and a device for obtaining a security key in a relay system are disclosed in the embodiment of the present invention. A node in the relay system obtains an initial key, according to the initial key, the node obtains a root key of an air interface protection key between the node and another node that is directly adjacent to the node, and according to the root key, the node obtains the air interface protection key between the node and said another node that is directly adjacent to the node. Therefore, according to the initial key, each lower-level node obtains a root key of an air interface protection key between each lower-level node, so that data of a UE on a Un interface link may be respectively protected, that is, each active UE has a set of security parameters on the Un interface link, and effective security protection is performed on data on each segment of an air interface.