RRC Connection Resume Security via Algorithm Reselection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 5G systems, there is a challenge in improving the security and flexibility of restoring a terminal's RRC connection from an inactive state to a connected state, especially due to high terminal mobility, which requires efficient management of encryption and integrity protection algorithms when the terminal handovers between base stations.
Innovation Solution
The method involves a terminal sending a connection resume request to a target base station, obtaining and using new encryption and integrity protection algorithms negotiated between the terminal and the base station, and sending a protected connection resume completion message to confirm the resumed RRC connection, allowing flexible selection and enhancement of security algorithms as the base station changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the terminal uses the same encryption and integrity protection algorithms negotiated with the source base station when resuming connection to the target base station, then the connection resume process is simple and fast, but the communication security is compromised because the algorithms are no longer optimized for the new base station
Solution Approach 1:
The patent applies preliminary action by having the target base station prepare and send the first encryption algorithm and first integrity protection algorithm to the terminal in advance, before the terminal needs to resume the connection. This allows the terminal to immediately use the new algorithms without performing complex negotiations during the connection resume process, thus improving security while maintaining simplicity.
Solution Approach 2:
The patent changes the security algorithm parameters from the second encryption algorithm and second integrity protection algorithm (used with the source base station) to the first encryption algorithm and first integrity protection algorithm (negotiated with the target base station). This parameter change ensures that the security algorithms are optimized for the new base station while the patent manages the transition to avoid excessive complexity.
2Reliability
If the terminal performs complex security algorithm negotiations with the target base station during connection resume, then the communication security is enhanced with new algorithms, but the connection resume time increases and productivity decreases
Solution Approach 1:
The target base station performs the security algorithm negotiation and prepares the first encryption algorithm and first integrity protection algorithm in advance, before the terminal initiates the connection resume. This preliminary action eliminates the need for time-consuming negotiations during the resume process, thus enhancing security without sacrificing connection resume speed.
Solution Approach 2:
The target base station autonomously selects and prepares appropriate security algorithms (first encryption algorithm and first integrity protection algorithm) based on its own capabilities and requirements, without requiring interactive negotiation with the terminal during the resume process. This self-service approach enhances security while maintaining fast connection resume.
3Reliability
If the terminal continuously updates encryption and integrity protection algorithms during connection resume, then the communication security is improved, but the processing overhead and device complexity increase
Solution Approach 1:
The target base station prepares the first encryption algorithm and first integrity protection algorithm in advance and sends them to the terminal in a single operation. This preliminary preparation avoids multiple iterative updates and negotiations, thus improving security while minimizing processing overhead and energy consumption.
Solution Approach 2:
The patent extracts the security algorithm negotiation process from the connection resume process itself, separating it into a preliminary preparation phase performed by the target base station. This extraction allows the resume process to proceed efficiently without the overhead of continuous algorithm updates, while still achieving enhanced security through the use of new algorithms.
Data Source
AI summary
This application provides an RRC connection resume method and apparatus. In the method, when a terminal moves to a target base station, the target base station may reselect, based on a capability and a requirement of the target base station, a first encryption algorithm and a first integrity protection algorithm that are used when the target base station communicates with the terminal, and send the first encryption algorithm and the first integrity protection algorithm to the terminal. On one hand, a security algorithm used for communication between the terminal and the target base station is flexibly selected. On the other hand, because the base station connected to the terminal changes, communication security can be improved by using a new encryption algorithm and integrity protection algorithm.


