RRC Inactive Security Key Derivation via NCC Chaining

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for user devices to transmit data securely while in a radio resource control (RRC) inactive state, as the release of access stratum (AS) resources complicates the determination of ciphering or integrity protection keys.

Innovation Solution

A method for security key derivation in a wireless system, involving the sending of an RRC suspend message with a next hop (NH) chaining counter (NCC) value, releasing AS resources, deriving a node key based on the NCC value, and unscrambling uplink messages using this key without allocating AS resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Use of energy by moving object

If AS resources are released when user device enters RRC inactive state, then energy consumption is reduced and device can operate in low-power mode, but security key determination becomes complicated and data transmission security is compromised

Engineering Contradiction:
Improveenergy consumptionVSAvoiddata transmission security
Core Design Contradiction:
Use of energy by moving objectVSReliability

Solution Approach 1:

The network side performs preliminary action by generating and storing the security key (K_RRC_INACTIVE) before the user device enters the inactive state. The security key is derived using the NCC value and other parameters, and is subsequently provided to the user device through secure channels. This allows the user device to have the necessary security key already available when transitioning to inactive state, eliminating the need for complex key determination during inactive state operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The network side acts as an intermediary by generating the security key on behalf of the user device and providing it through a secure key delivery mechanism. This intermediary approach resolves the contradiction by allowing the user device to operate in inactive state with pre-provided security keys, maintaining data transmission security without requiring the user device to perform complex key derivation operations while in low-power mode.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security keys are derived by user device in inactive state, then data transmission can be secured, but device complexity and computational requirements increase

Engineering Contradiction:
Improvedata transmission securityVSAvoidsecurity key derivation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The complex security key derivation function is extracted from the user device and relocated to the network side. The network side performs the computationally intensive key derivation operations using the NCC value and other parameters, then provides the resulting security key to the user device. This extraction reduces the computational burden and complexity requirements for the user device, especially important when the device is in inactive state with limited processing resources.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The network side provides self-service by automatically generating and managing the security keys for inactive state transmissions. Instead of requiring the user device to independently perform complex key derivation operations, the network side autonomously handles the key generation and delivery process, simplifying the user device's role to merely receiving and using the provided security keys.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If NCC value is transmitted to network side, then security key can be derived for multiple nodes, but information security and key management complexity increase

Engineering Contradiction:
Improvesecurity key applicability to multiple nodesVSAvoidinformation security
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The security key management implements local quality by providing different security keys to different nodes based on their specific requirements. The network side derives and provides security keys tailored to each node's context, ensuring that each node receives appropriate security credentials without exposing all NCC values or security parameters to all nodes. This localized approach maintains information security while enabling versatile key derivation for multiple nodes.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system uses parameter changes in the form of different NCC values to derive different security keys for different nodes or transmission contexts. By changing the NCC parameter, the network side can generate a family of related security keys that maintain cryptographic relationships while being distinct for different purposes. This allows adaptable security key generation for multiple nodes while maintaining information security through controlled parameter variation rather than exposing complete key material.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12238514B2Security key generation for handling data transmissions from user devices in an inactive state
Publication Date: 2025.02.25 APPLE INC
  • US12238514B2 patent drawing
  • US12238514B2 patent drawing
  • US12238514B2 patent drawing

AI summary

An example technique for security key derivation in a wireless system includes: sending a radio resource control (RRC) suspend message from a first node, to a first user device, the RRC suspend message including a first next hop (NH) chaining counter (NCC) value; releasing access stratum (AS) resources associated with the first user device; deriving a first node key based on the first NCC value; receiving a first uplink message from the first user device without allocating AS resources to the first user device; and unscrambling the first uplink message based on the first NCC value.