Enhanced Security Context Transition from UTRAN to E-UTRAN
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security protocols in UMTS and GERAN networks face challenges in maintaining secure key management, particularly when transitioning to E-UTRAN networks, as frequent key changes are cumbersome due to overhead and exposed RNC functionalities, leading to potential security breaches if both cipher and integrity keys are compromised.
Innovation Solution
A method for transitioning an enhanced security context from UTRAN/GERAN-based serving networks to E-UTRAN-based serving networks by generating session keys using a first root key and information elements, allowing the remote station to derive a new root key for secure wireless communications without exposing existing keys outside the core network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If AKA authentication is run frequently to change keys, then security is improved, but overhead and complexity increase significantly
Solution Approach 1:
The patent implements dynamic key derivation where session keys are continuously refreshed based on changing physical layer conditions (channel quality indicators, signal strength) without triggering full AKA authentication. This allows the security context to adapt dynamically to security threats while avoiding the overhead of frequent re-authentication.
Solution Approach 2:
The patent performs preliminary key derivation by pre-generating multiple session keys from the master key before they are needed. When security threats are detected or time expires, pre-computed keys can be immediately activated without waiting for AKA authentication, thus maintaining security while reducing overhead.
2Adaptability or versatility
If RNC functionality is deployed in exposed locations like Home Node B, then network flexibility is improved, but key compromise risk increases
Solution Approach 1:
The patent segments the security architecture by separating the master key storage (kept secure in core network) from session key usage (distributed to RNC). This allows RNC functionality to be deployed flexibly in exposed locations while the critical master keys remain protected in centralized secure locations.
Solution Approach 2:
The patent introduces session keys as intermediaries between the master key and actual encryption operations. Session keys are derived from master keys but can be safely distributed to exposed RNC locations, acting as a protective intermediary that prevents direct exposure of master keys while enabling flexible deployment.
3Reliability
If session keys are used to lower security risks, then security is improved, but key management complexity increases
Solution Approach 1:
The patent implements self-service key management where the system automatically derives, distributes, and refreshes session keys based on pre-defined policies and physical layer measurements without manual intervention. This automation reduces key management complexity while maintaining enhanced security through frequent session key rotation.
4Reliability
If keys are changed at next AKA authentication, then compromised keys are refreshed, but AKA authentication overhead is significant
Solution Approach 1:
The patent implements periodic session key refreshment based on time intervals and physical layer measurements rather than waiting for AKA authentication. This periodic action ensures key freshness and security while avoiding the significant overhead of full AKA authentication, as keys are refreshed through lighter-weight derivation processes.
Data Source
AI summary
Disclosed is a method for transitioning an enhanced security context from a UTRAN/GERAN-based serving network to an E-UTRAN-based serving network. In the method, the remote station the remote station generates first and second session keys, in accordance with the enhanced security context, using a first enhanced security context root key associated with a UTRAN/GERAN-based serving network and a first information element. The remote station receives a first message from the E-UTRAN-based serving network. The first message signals to the remote station to generate a second enhanced security context root key for use with the E-UTRAN-based serving network. The remote station generates, in response to the first message, the second enhanced security context root key from the first enhanced security context root key using the s first and second session keys as inputs. The remote station protects wireless communications, on the E-UTRAN-based serving network, based on the second enhanced security context root key.


