Security Context Handling for Intersystem Mobility
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge in mobile communication networks lies in negotiating key usage during idle mode mobility or handover between E-UTRAN and other radio access networks, particularly when user equipment and E-UTRAN have or do not have cached security contexts.
Innovation Solution
A method involving the use of key identifiers to identify and verify messages using either mapped or cached security contexts, with the ability to activate the cached security context through a security mode command procedure, ensuring secure handover and tracking area updates by correctly selecting and using keys associated with these contexts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If both mapped and cached security contexts are maintained during mobility, then security verification flexibility is improved, but device complexity increases
Solution Approach 1:
The patent segments the security context into two distinct types: mapped security context (for active mode handover) and cached security context (for idle mode mobility). Each context type is managed separately with its own key identifiers (KSI/CKSN for mapped, KSI ASME for cached), allowing the system to select the appropriate context based on mobility scenario without mixing management protocols.
Solution Approach 2:
The patent implements dynamic selection between mapped and cached security contexts based on the mobility state and network configuration. The system can switch between using mapped contexts (when available and appropriate) and cached contexts (when moving between different radio access networks in idle mode), optimizing security verification for each specific scenario.
2Measurement precision
If key identifiers for both mapped and cached security contexts are included in messages, then message verification accuracy is improved, but information overhead increases
Solution Approach 1:
The patent includes both mapped security context identifier (KSI/CKSN) and cached security context identifier (KSI ASME) in mobility messages, but only activates verification using the relevant identifier based on the current mobility scenario. This partial action approach ensures both identifiers are available for verification accuracy when needed, while the system selectively processes only the necessary one to minimize effective overhead.
Data Source
Figure 1A
Figure 1B
Figure 2A
AI summary
A method and apparatus for intersystem mobility security context handling between different radio access networks which can include a receiver configured to receive a tracking area update message from a user terminal. The message can include a first key identifier configured to identify a mapped security context and a second key identifier configured to identify a cached security context. A verifier can be configured to verify the tracking area update message with a key identified by the first or second key identifier.