RRC Connection Resume Security via Algorithm Reselection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G systems, there is a challenge in improving the security and flexibility of restoring a terminal's RRC connection from an inactive state to a connected state, especially due to high terminal mobility, which requires efficient management of encryption and integrity protection algorithms when the terminal handovers between base stations.

Innovation Solution

The method involves a terminal sending a connection resume request to a target base station, obtaining and using new encryption and integrity protection algorithms negotiated between the terminal and the base station, and sending a protected connection resume completion message to confirm the resumed RRC connection, allowing flexible selection and enhancement of security algorithms as the base station changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the terminal uses the same encryption and integrity protection algorithms negotiated with the source base station when resuming connection to the target base station, then the connection resume process is simple and fast, but the communication security is compromised because the algorithms are no longer optimized for the new base station

Engineering Contradiction:
Improvecommunication securityVSAvoidalgorithm negotiation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by having the target base station prepare and send the first encryption algorithm and first integrity protection algorithm to the terminal in advance, before the terminal needs to resume the connection. This allows the terminal to immediately use the new algorithms without performing complex negotiations during the connection resume process, thus improving security while maintaining simplicity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the security algorithm parameters from the second encryption algorithm and second integrity protection algorithm (used with the source base station) to the first encryption algorithm and first integrity protection algorithm (negotiated with the target base station). This parameter change ensures that the security algorithms are optimized for the new base station while the patent manages the transition to avoid excessive complexity.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If the terminal performs complex security algorithm negotiations with the target base station during connection resume, then the communication security is enhanced with new algorithms, but the connection resume time increases and productivity decreases

Engineering Contradiction:
Improvecommunication securityVSAvoidconnection resume speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The target base station performs the security algorithm negotiation and prepares the first encryption algorithm and first integrity protection algorithm in advance, before the terminal initiates the connection resume. This preliminary action eliminates the need for time-consuming negotiations during the resume process, thus enhancing security without sacrificing connection resume speed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The target base station autonomously selects and prepares appropriate security algorithms (first encryption algorithm and first integrity protection algorithm) based on its own capabilities and requirements, without requiring interactive negotiation with the terminal during the resume process. This self-service approach enhances security while maintaining fast connection resume.

Inventive Principle:
Principle #25Self-service

3Reliability

If the terminal continuously updates encryption and integrity protection algorithms during connection resume, then the communication security is improved, but the processing overhead and device complexity increase

Engineering Contradiction:
Improvecommunication securityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The target base station prepares the first encryption algorithm and first integrity protection algorithm in advance and sends them to the terminal in a single operation. This preliminary preparation avoids multiple iterative updates and negotiations, thus improving security while minimizing processing overhead and energy consumption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the security algorithm negotiation process from the connection resume process itself, separating it into a preliminary preparation phase performed by the target base station. This extraction allows the resume process to proceed efficiently without the overhead of continuous algorithm updates, while still achieving enhanced security through the use of new algorithms.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11564099B2RRC connection resume method and apparatus
Publication Date: 2023.01.24 HUAWEI TECH CO LTD
  • US11564099B2 patent drawing
  • US11564099B2 patent drawing
  • US11564099B2 patent drawing

AI summary

This application provides an RRC connection resume method and apparatus. In the method, when a terminal moves to a target base station, the target base station may reselect, based on a capability and a requirement of the target base station, a first encryption algorithm and a first integrity protection algorithm that are used when the target base station communicates with the terminal, and send the first encryption algorithm and the first integrity protection algorithm to the terminal. On one hand, a security algorithm used for communication between the terminal and the target base station is flexibly selected. On the other hand, because the base station connected to the terminal changes, communication security can be improved by using a new encryption algorithm and integrity protection algorithm.