Conditional RRC Security Key Management in LTE

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the LTE system, the conventional method for processing RRC connection reestablishment involves unnecessary key updates, leading to increased computational load and time delay, even when no security issues or changes occur, resulting in inefficient resource utilization.

Innovation Solution

A method that includes a judgment step to determine whether a new access layer security key is needed during RRC connection reestablishment, allowing the eNB and UE to either generate or reuse existing keys based on specific conditions such as handover type, security status, and next hop chaining count, thereby optimizing key management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the access layer security key is updated during RRC connection reestablishment regardless of whether security issues occur, then the security protection mechanism is maintained, but the computational load and time delay increase significantly

Engineering Contradiction:
Improvesecurity protectionVSAvoidtime delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies dynamics by making the key update process conditional rather than fixed. The eNB dynamically determines whether to perform key update based on real-time judgment of security status, handover type, and NCC values. This transforms the static mandatory key update into a dynamic conditional operation, reducing unnecessary computations while maintaining security when needed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent utilizes parameter changes by introducing judgment parameters (security status, handover type, NCC values) that determine whether key update should occur. The system changes the state of key update from always-executing to conditionally-executing based on these parameter evaluations, optimizing the balance between security and efficiency.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If the access layer security key is updated during RRC connection reestablishment regardless of whether security issues occur, then the security protection mechanism is maintained, but the computational load increases significantly

Engineering Contradiction:
Improvesecurity protectionVSAvoidcomputational load
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The patent applies dynamics by making the key update process conditional rather than fixed. The eNB dynamically determines whether to perform key update based on real-time judgment of security status, handover type, and NCC values. This transforms the static mandatory key update into a dynamic conditional operation, reducing unnecessary computations while maintaining security when needed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent utilizes parameter changes by introducing judgment parameters (security status, handover type, NCC values) that determine whether key update should occur. The system changes the state of key update from always-executing to conditionally-executing based on these parameter evaluations, optimizing the balance between security and efficiency.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If the access layer security key is updated during RRC connection reestablishment regardless of whether security issues occur, then the security protection mechanism is maintained, but the resource utilization becomes inefficient

Engineering Contradiction:
Improvesecurity protectionVSAvoidresource utilization
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies dynamics by making the key update process conditional rather than fixed. The eNB dynamically determines whether to perform key update based on real-time judgment of security status, handover type, and NCC values. This transforms the static mandatory key update into a dynamic conditional operation, reducing unnecessary computations while maintaining security when needed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent utilizes parameter changes by introducing judgment parameters (security status, handover type, NCC values) that determine whether key update should occur. The system changes the state of key update from always-executing to conditionally-executing based on these parameter evaluations, optimizing the balance between security and efficiency.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2453684B1Security key processing method, device and system for radio resource control (RRC) connection re-establishing
Publication Date: 2019.02.27 ZTE CORP
  • EP2453684B1 patent drawingFigure 1
  • EP2453684B1 patent drawingFigure 2
  • EP2453684B1 patent drawingFigure 3

AI summary

A method for processing a security key when a Radio Resource Control (RRC) connection is reestablished is provided, which comprises: receiving a Radio Resource Control connection reestablishment request from a user equipment by a node B; the node B judging whether there is a need to generate a new access layer security key, and generating the new access layer security key or using an original access layer security key based on this judgment result; and sending corresponding Radio Resource Control connection reestablishment information to the user equipment by the node B, so that the user equipment carries out the connection reestablishment. The method adds in the judgment steps into the process of generating an access layer security key, and thus solving the problem in the conventional method that a new key is generated regardless of the situation, thereby saving a large number of computation process of generating the key and reducing the time delay of the systems.