Remote Station Security Context Transition Mechanism

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security protocols in UMTS, GERAN, and LTE networks face challenges in maintaining secure communications due to the potential compromise of shared keys, especially in exposed RNC functionalities, and the need for interoperability with both enhanced and legacy network nodes.

Innovation Solution

A method for transitioning a remote station from a current serving network node with a first security context to a new node with a different security context, involving the use of legacy keys and session keys to ensure secure communication, even if the new node does not support the original security context, by generating session keys based on an information element associated with the first security context and determining the support of the new node through message authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If session keys are used to lower security risks in exposed RNC functionality, then security is improved, but network upgrade modifications are required which increases device complexity and deployment difficulty

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork upgrade modifications
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a key derivation function as an intermediary mechanism that transforms existing shared keys (CK, IK) into session keys through a mathematical function. This intermediary approach enables enhanced security without requiring fundamental changes to the network architecture or deployment procedures, as the key derivation can be implemented through software updates rather than hardware modifications.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the security parameter by deriving session keys from existing shared keys using a key derivation function. Instead of replacing the entire key management system, the solution modifies the key parameters by creating derived keys (session keys) that provide enhanced security properties while maintaining compatibility with existing network infrastructure and authentication mechanisms.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If AKA authentication is run frequently to change compromised keys, then security is improved, but network overhead increases significantly

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent performs preliminary key derivation by deriving session keys from shared keys before actual communication occurs. This preliminary action ensures that even if shared keys are compromised during communication, the session keys already derived provide a security buffer. The session keys can be derived once and used for multiple communications, avoiding the need for frequent full AKA authentication cycles.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent maintains continuous security by deriving session keys that can be used repeatedly without requiring repeated AKA authentication. The session keys provide ongoing security protection for communications, allowing the useful action of secure communication to continue without interruption or frequent overhead-inducing re-authentication cycles.

Inventive Principle:
Principle #20Continuity of useful action

3Adaptability or versatility

If remote stations support both enhanced and legacy security contexts, then interoperability is improved, but device complexity increases

Engineering Contradiction:
ImproveinteroperabilityVSAvoidsecurity context management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal key derivation mechanism that works with both enhanced and legacy security contexts. The key derivation function can process different types of input keys (CK, IK from AKA authentication) and produce appropriate session keys for various network node types. This multi-functional approach allows a single implementation to support interoperability across different security contexts without requiring separate handling logic for each context type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2559292B1Apparatus and method for transitioning from a serving network node that supports an enhanced security context to a legacy serving network node
Publication Date: 2017.07.26 QUALCOMM INC
  • EP2559292B1 patent drawingFigure 1~8
  • EP2559292B1 patent drawingFigure 2~3
  • EP2559292B1 patent drawingFigure 4

AI summary

Disclosed is a method for transitioning a remote station from a current serving network node having an enhanced security context to a new serving network node. In the method, the remote station provides at least one legacy key, and generates at least one session key based on an information element associated with the enhanced security context. The remote station forwards a first message having the information element to the new serving network node. The remote station receives a second message, from the new serving network node, having a response based on either the legacy key or the session key. The remote station determines that the new serving network node does not support the enhanced security context if the response of the second message is based on the legacy key. Accordingly, the remote station protects communications based on the legacy key upon determining that the enhanced security context is not supported.