Security Key Context Distribution for Carrier Aggregation Path Switches
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Carrier aggregation between base stations in LTE systems leads to frequent path switches, causing network security synchronization issues and call drops due to the difference in bearer handover processes compared to X2 handovers.
Innovation Solution
A method is introduced to distribute a security key context and utilize a mobility management entity to manage path switches, keeping the security key context unchanged during carrier aggregation, and prioritizing paths to reduce bearer release and UE detachment by using the original path or paths with higher priority.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If path switch procedure is performed for each bearer handover in carrier aggregation between base stations, then data offloading capability is improved, but network security synchronization deteriorates causing call drops
Solution Approach 1:
The patent applies preliminary action by performing a security key update only when necessary (when security context changes) rather than updating it with every path switch. The MME determines whether security key update is needed before proceeding, and the eNB is instructed to update or maintain the current security context based on this determination, preventing unnecessary security context changes that would cause synchronization issues.
Solution Approach 2:
The patent changes the parameter of security key update frequency from 'every path switch' to 'conditional based on security context changes'. The MME evaluates whether security context has changed and only triggers security key updates when necessary, thereby maintaining security synchronization while allowing frequent path switches for data offloading.
2Productivity
If frequent path switches are performed during carrier aggregation, then carrier aggregation functionality is improved, but network security synchronization deteriorates
Solution Approach 1:
The MME performs a preliminary determination of whether security context has changed before executing a security key update after each path switch. This preliminary check allows frequent path switches to proceed without unnecessary security updates, maintaining security synchronization while preserving carrier aggregation functionality.
Solution Approach 2:
The patent changes the security update parameter from a fixed 'update after every path switch' to a dynamic parameter that depends on whether security context has actually changed. This allows the system to maintain high productivity through frequent path switches while avoiding the reliability issue of unnecessary security updates.
3Reliability
If security key context is updated with each path switch, then security freshness is improved, but network stability deteriorates due to synchronization loss
Solution Approach 1:
The MME performs a preliminary evaluation to determine if security context has changed before triggering a security key update. This preliminary action ensures that security updates occur only when necessary for security freshness, while avoiding unnecessary updates that would disrupt network stability and cause UE detachment.
Solution Approach 2:
The patent changes the security key update parameter from a fixed frequency (every path switch) to a conditional parameter based on security context changes. This maintains security freshness by updating keys when needed while improving network stability by avoiding unnecessary updates that would cause synchronization loss.
4Adaptability or versatility
If path switch procedure is performed for each bearer handover, then bearer mobility is improved, but the number of path switch operations increases causing security desynchronization
Solution Approach 1:
The MME performs a preliminary determination of whether security context has changed before executing security key updates after path switches. This preliminary check reduces the number of actual security update operations while maintaining bearer mobility, as updates occur only when security context changes rather than with every path switch.
Solution Approach 2:
The patent changes the security update parameter from a fixed 'update after every path switch' to a dynamic parameter based on security context changes. This reduces the number of security update operations (lowering device complexity) while maintaining bearer mobility, as the system adapts the update frequency to actual security needs.
Data Source
Figure 1-a
Figure 1-b
Figure 2~3
AI summary
Embodiments of the present invention disclose a method of distributing a security key context, a mobility management entity, and a base station, where the method of distributing a security key context includes: receiving, by a mobility management entity, a first indication from a primary base station, where the first indication is used for requesting a path switch from the mobility management entity and indicating that the path switch is triggered by carrier aggregation between base stations; processing the path switch according to the first indication; and according to the first indication, keeping a security key context for the path switch unchanged, and sending a second indication to the primary base station, to indicate the primary base station to keep the security key context unchanged; or sending a third indication to the primary base station, to indicate the primary base station to acquire a quantity of times of reversal of a next hop chaining counter in the security key context. It should be noted that, technical solutions provided in the present invention can effectively improve reliability of a path switch during carrier aggregation between base stations.