Conditional RRC Security Key Management in LTE
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the LTE system, the conventional method for processing RRC connection reestablishment involves unnecessary key updates, leading to increased computational load and time delay, even when no security issues or changes occur, resulting in inefficient resource utilization.
Innovation Solution
A method that includes a judgment step to determine whether a new access layer security key is needed during RRC connection reestablishment, allowing the eNB and UE to either generate or reuse existing keys based on specific conditions such as handover type, security status, and next hop chaining count, thereby optimizing key management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the access layer security key is updated during RRC connection reestablishment regardless of whether security issues occur, then the security protection mechanism is maintained, but the computational load and time delay increase significantly
Solution Approach 1:
The patent applies dynamics by making the key update process conditional rather than fixed. The eNB dynamically determines whether to perform key update based on real-time judgment of security status, handover type, and NCC values. This transforms the static mandatory key update into a dynamic conditional operation, reducing unnecessary computations while maintaining security when needed.
Solution Approach 2:
The patent utilizes parameter changes by introducing judgment parameters (security status, handover type, NCC values) that determine whether key update should occur. The system changes the state of key update from always-executing to conditionally-executing based on these parameter evaluations, optimizing the balance between security and efficiency.
2Reliability
If the access layer security key is updated during RRC connection reestablishment regardless of whether security issues occur, then the security protection mechanism is maintained, but the computational load increases significantly
Solution Approach 1:
The patent applies dynamics by making the key update process conditional rather than fixed. The eNB dynamically determines whether to perform key update based on real-time judgment of security status, handover type, and NCC values. This transforms the static mandatory key update into a dynamic conditional operation, reducing unnecessary computations while maintaining security when needed.
Solution Approach 2:
The patent utilizes parameter changes by introducing judgment parameters (security status, handover type, NCC values) that determine whether key update should occur. The system changes the state of key update from always-executing to conditionally-executing based on these parameter evaluations, optimizing the balance between security and efficiency.
3Reliability
If the access layer security key is updated during RRC connection reestablishment regardless of whether security issues occur, then the security protection mechanism is maintained, but the resource utilization becomes inefficient
Solution Approach 1:
The patent applies dynamics by making the key update process conditional rather than fixed. The eNB dynamically determines whether to perform key update based on real-time judgment of security status, handover type, and NCC values. This transforms the static mandatory key update into a dynamic conditional operation, reducing unnecessary computations while maintaining security when needed.
Solution Approach 2:
The patent utilizes parameter changes by introducing judgment parameters (security status, handover type, NCC values) that determine whether key update should occur. The system changes the state of key update from always-executing to conditionally-executing based on these parameter evaluations, optimizing the balance between security and efficiency.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method for processing a security key when a Radio Resource Control (RRC) connection is reestablished is provided, which comprises: receiving a Radio Resource Control connection reestablishment request from a user equipment by a node B; the node B judging whether there is a need to generate a new access layer security key, and generating the new access layer security key or using an original access layer security key based on this judgment result; and sending corresponding Radio Resource Control connection reestablishment information to the user equipment by the node B, so that the user equipment carries out the connection reestablishment. The method adds in the judgment steps into the process of generating an access layer security key, and thus solving the problem in the conventional method that a new key is generated regardless of the situation, thereby saving a large number of computation process of generating the key and reducing the time delay of the systems.