RRC Security Mode Control for SRVCC Inter-RAT Handovers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

During inter-RAT handovers, especially from E-UTRAN to UTRAN, the integrity protection for the packet-switched domain is not activated, leading to failed Routing Area Update procedures and poor user experience due to missing integrity protection in the PS domain, causing issues with multi-RAB handovers and SRVCC scenarios.

Innovation Solution

The user equipment (UE) is configured to supervise integrity protection activation in both circuit-switched and packet-switched domains, ensuring that layer 3 signaling messages are only processed after successful integrity protection in each domain, and upon receiving a Security Mode Command, it activates integrity protection for the CS domain while indicating successful security mode control procedures to both mobility management layers, ensuring seamless handovers by adding an indicator to the Routing Area Update message to trigger the security mode control for the PS domain.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If integrity protection is activated only for CS domain during handover, then security control procedure for CS domain can be completed successfully, but PS domain remains without integrity protection causing failed Routing Area Update procedures

Engineering Contradiction:
Improveintegrity protection activationVSAvoidRouting Area Update procedure
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the security mode control procedure into separate CS domain and PS domain procedures. When a Security Mode Command is received, the UE identifies whether it applies to CS domain, PS domain, or both, and executes the appropriate security activation independently for each domain, allowing both domains to have integrity protection activated simultaneously

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements feedback mechanisms where the UE monitors the activation status of integrity protection in both CS and PS domains. The UE uses this feedback information to determine when to proceed with Routing Area Update procedures and ensures that security mode control is properly completed for the relevant domain before continuing operations

Inventive Principle:
Principle #23Feedback

2Reliability

If separate security mode procedures are initiated for both CS and PS domains, then integrity protection is ensured for both domains, but signaling overhead and procedure complexity increase

Engineering Contradiction:
Improveintegrity protectionVSAvoidsecurity mode control procedure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the security mode control procedures by allowing a single Security Mode Command from the network to trigger security activation for both CS and PS domains simultaneously. The UE processes the command and activates integrity protection in both domains in one unified procedure, avoiding the need for separate independent security mode procedures for each domain

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent makes the Security Mode Command message universal by enabling it to apply to both CS and PS domains depending on the domain indicator field. A single Security Mode Command can configure security parameters for one or both domains, making the procedure multi-functional and reducing overall signaling overhead

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2976910B1Security mode control of the RRC protocol in case of multi-RAB sr-vcc or mdt inter-rat handovers to utran
Publication Date: 2021.01.20 NOKIA SOLUTIONS & NETWORKS OY
  • EP2976910B1 patent drawingFigure 1
  • EP2976910B1 patent drawingFigure 2
  • EP2976910B1 patent drawingFigure 3

AI summary

The application relates to the RRC protocol as standardised in TS 25.331 and in particular addresses the problem that the Routing Area Update procedure does not work properly after the SRVCC with PS and CS RABs from E-UTRAN to UTRAN. Problematic Scenario: 1. CS CN and PS CN send Relocation Request for the handover to UTRAN due to PS + CS SRVCC triggered from E-UTRA 2. During the handover procedure, latest CN domain for which ciphering and integrity protection is configured for Signaling RAB is CS CN as specified in TS25.331 clause 8.3.6.3. 3. SRBs can have only one latest CN domain to which ciphering is configured. So it can be CS or PS and now it is CS (see step 2). This can mean there is no integrity protection started for the PS CN. This is not needed since SRB data is integrity protected, (according to TS 33.102 clause 6.5.4) "The signalling radio bearers are used for transfer of signalling data for services delivered by both CS and PS service domains. These signalling radio bearers are data integrity protected by the IK of the service domain for which the most recent security mode negotiation took place." 4. UE triggers Routing Area Update and PS CN sends Routing Area Update Accept. 5.UE does not accept NAS messages from SGSN (i.e, Routing Area Update Accept) as it considers that PS integrity protection is not activated. To solve the problem explained above, following two possible solutions are proposed 1. Upon first SMC procedure after SRVCC HO, UE activates integrity protection using the integrity key of the key set used. If "RAB info" contains both CS and PS RABs, UE AS layer shall indicate to the upper layers of CS and PS domain, i.e. MM and GMM, that integrity protection is activated (315). 2. Upon SRVCC HO, UE adds an indicator in the RAU performed towards the SGSN to trigger "SMC" procedure for PS domain.