Security Context Handling for Intersystem Mobility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge in mobile communication networks lies in negotiating key usage during idle mode mobility or handover between E-UTRAN and other radio access networks, particularly when user equipment and E-UTRAN have or do not have cached security contexts.

Innovation Solution

A method involving the use of key identifiers to identify and verify messages using either mapped or cached security contexts, with the ability to activate the cached security context through a security mode command procedure, ensuring secure handover and tracking area updates by correctly selecting and using keys associated with these contexts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If both mapped and cached security contexts are maintained during mobility, then security verification flexibility is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity verification flexibilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security context into two distinct types: mapped security context (for active mode handover) and cached security context (for idle mode mobility). Each context type is managed separately with its own key identifiers (KSI/CKSN for mapped, KSI ASME for cached), allowing the system to select the appropriate context based on mobility scenario without mixing management protocols.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic selection between mapped and cached security contexts based on the mobility state and network configuration. The system can switch between using mapped contexts (when available and appropriate) and cached contexts (when moving between different radio access networks in idle mode), optimizing security verification for each specific scenario.

Inventive Principle:
Principle #15Dynamics

2Measurement precision

If key identifiers for both mapped and cached security contexts are included in messages, then message verification accuracy is improved, but information overhead increases

Engineering Contradiction:
Improvemessage verification accuracyVSAvoidinformation overhead
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent includes both mapped security context identifier (KSI/CKSN) and cached security context identifier (KSI ASME) in mobility messages, but only activates verification using the relevant identifier based on the current mobility scenario. This partial action approach ensures both identifiers are available for verification accuracy when needed, while the system selectively processes only the necessary one to minimize effective overhead.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP2272277B1Intersystem mobility security context handling between different radio access networks
Publication Date: 2019.11.20 NOKIA TECHNOLOGIES OY
  • EP2272277B1 patent drawingFigure 1A
  • EP2272277B1 patent drawingFigure 1B
  • EP2272277B1 patent drawingFigure 2A

AI summary

A method and apparatus for intersystem mobility security context handling between different radio access networks which can include a receiver configured to receive a tracking area update message from a user terminal. The message can include a first key identifier configured to identify a mapped security context and a second key identifier configured to identify a cached security context. A verifier can be configured to verify the tracking area update message with a key identified by the first or second key identifier.