RRC Resume Key Derivation for LTE Handover
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The RRC Resume procedure in LTE networks faces issues with ambiguous key derivation and encryption algorithm compatibility when a UE is suspended in one cell and resumes in another, leading to potential decryption failures and security breaches.
Innovation Solution
The method involves the eNB indicating key derivation parameters and security algorithms during suspension, allowing the UE to compute the correct AS base key for the resuming eNB, ensuring seamless encryption and decryption across cell transitions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of time
If the UE context is stored in the eNB for RRC Resume procedure, then the signalling overhead is reduced and connection resumption is faster, but the key derivation becomes ambiguous when transitioning between different eNBs, leading to potential decryption failures
Solution Approach 1:
The patent applies preliminary action by pre-computing and storing the AS base key (KeNB*) in the UE context during the RRC suspension phase, before the actual connection resumption occurs. This pre-computed key is derived using the Next Hop (NH) parameter and is valid for use with any eNB that retrieves the UE context, enabling immediate encryption without key derivation delays while ensuring consistent key usage across eNB transitions.
Solution Approach 2:
The patent introduces the Next Hop (NH) parameter as an intermediary element that mediates key derivation between the UE and potentially different eNBs. The NH parameter serves as a shared secret that both the UE and the retrieving eNB use to derive the same AS base key (KeNB*), ensuring cryptographic compatibility without requiring direct key exchange or ambiguous derivation processes when transitioning between eNBs.
2Productivity
If the UE transitions quickly from RRC Idle to RRC Connected state, then productivity is improved for MTC devices, but security risks increase due to potential key derivation ambiguities and clear text transmission vulnerabilities
Solution Approach 1:
The patent applies preliminary action by pre-establishing the AS base key (KeNB*) during the suspension phase and including it in the stored UE context. This allows the UE to immediately use encrypted channels upon connection resumption without undergoing time-consuming key derivation procedures, thereby maintaining high productivity while ensuring security through pre-validated cryptographic keys.
Solution Approach 2:
The patent uses copying by having the eNB retrieve and copy the pre-computed AS base key (KeNB*) from the stored UE context during the resumption process. This copied key is then used by both the eNB and UE for symmetric encryption, ensuring that both parties use identical cryptographic material without requiring complex key exchange protocols, thus maintaining security while enabling fast connection restoration.
3Adaptability or versatility
If the eNB stores complete UE context including security parameters, then adaptability is improved for seamless handover, but the complexity of key management and synchronization increases
Solution Approach 1:
The patent extracts only the essential security element (the AS base key KeNB*) from the complete security context and stores it separately in the UE context information, while the UE maintains the master key (KeNB) and other security parameters locally. This extraction reduces the complexity of what needs to be transmitted and stored in the network, while still providing all necessary information for seamless handover and connection resumption.
Solution Approach 2:
The patent changes the parameter representation by transforming the master key (KeNB) into a derived AS base key (KeNB*) using the Next Hop (NH) parameter through a key derivation function. This parameter transformation creates a more suitable form for storage and transmission in the UE context, as the derived key is specifically tailored for use with the NH-based handover mechanism, simplifying the overall key management architecture.
Data Source
AI summary
According to an exemplary embodiment, there is provided a method of operating a terminal device. The method includes operating the terminal device in a connected state with respect to the communication network. The method further includes receiving a first signal from a first radio access node in the communication network indicating that the connected state is to be suspended, the first signal having information for use in determining a first key for encrypting data to be sent between the terminal device and the first radio access node or another radio access node in the communication network if the connected state is resumed.


