Security Key Context Distribution for Carrier Aggregation Path Switches

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Carrier aggregation between base stations in LTE systems leads to frequent path switches, causing network security synchronization issues and call drops due to the difference in bearer handover processes compared to X2 handovers.

Innovation Solution

A method is introduced to distribute a security key context and utilize a mobility management entity to manage path switches, keeping the security key context unchanged during carrier aggregation, and prioritizing paths to reduce bearer release and UE detachment by using the original path or paths with higher priority.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If path switch procedure is performed for each bearer handover in carrier aggregation between base stations, then data offloading capability is improved, but network security synchronization deteriorates causing call drops

Engineering Contradiction:
Improvedata offloading capabilityVSAvoidnetwork security synchronization
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by performing a security key update only when necessary (when security context changes) rather than updating it with every path switch. The MME determines whether security key update is needed before proceeding, and the eNB is instructed to update or maintain the current security context based on this determination, preventing unnecessary security context changes that would cause synchronization issues.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the parameter of security key update frequency from 'every path switch' to 'conditional based on security context changes'. The MME evaluates whether security context has changed and only triggers security key updates when necessary, thereby maintaining security synchronization while allowing frequent path switches for data offloading.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If frequent path switches are performed during carrier aggregation, then carrier aggregation functionality is improved, but network security synchronization deteriorates

Engineering Contradiction:
Improvecarrier aggregation functionalityVSAvoidnetwork security synchronization
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The MME performs a preliminary determination of whether security context has changed before executing a security key update after each path switch. This preliminary check allows frequent path switches to proceed without unnecessary security updates, maintaining security synchronization while preserving carrier aggregation functionality.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the security update parameter from a fixed 'update after every path switch' to a dynamic parameter that depends on whether security context has actually changed. This allows the system to maintain high productivity through frequent path switches while avoiding the reliability issue of unnecessary security updates.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If security key context is updated with each path switch, then security freshness is improved, but network stability deteriorates due to synchronization loss

Engineering Contradiction:
Improvesecurity freshnessVSAvoidnetwork stability
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The MME performs a preliminary evaluation to determine if security context has changed before triggering a security key update. This preliminary action ensures that security updates occur only when necessary for security freshness, while avoiding unnecessary updates that would disrupt network stability and cause UE detachment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the security key update parameter from a fixed frequency (every path switch) to a conditional parameter based on security context changes. This maintains security freshness by updating keys when needed while improving network stability by avoiding unnecessary updates that would cause synchronization loss.

Inventive Principle:
Principle #35Parameter changes

4Adaptability or versatility

If path switch procedure is performed for each bearer handover, then bearer mobility is improved, but the number of path switch operations increases causing security desynchronization

Engineering Contradiction:
Improvebearer mobilityVSAvoidnumber of path switch operations
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The MME performs a preliminary determination of whether security context has changed before executing security key updates after path switches. This preliminary check reduces the number of actual security update operations while maintaining bearer mobility, as updates occur only when security context changes rather than with every path switch.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the security update parameter from a fixed 'update after every path switch' to a dynamic parameter based on security context changes. This reduces the number of security update operations (lowering device complexity) while maintaining bearer mobility, as the system adapts the update frequency to actual security needs.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3079390B1Security key context distribution method, mobile management entity, and base station
Publication Date: 2019.09.04 HUAWEI TECH CO LTD
  • EP3079390B1 patent drawingFigure 1-a
  • EP3079390B1 patent drawingFigure 1-b
  • EP3079390B1 patent drawingFigure 2~3

AI summary

Embodiments of the present invention disclose a method of distributing a security key context, a mobility management entity, and a base station, where the method of distributing a security key context includes: receiving, by a mobility management entity, a first indication from a primary base station, where the first indication is used for requesting a path switch from the mobility management entity and indicating that the path switch is triggered by carrier aggregation between base stations; processing the path switch according to the first indication; and according to the first indication, keeping a security key context for the path switch unchanged, and sending a second indication to the primary base station, to indicate the primary base station to keep the security key context unchanged; or sending a third indication to the primary base station, to indicate the primary base station to acquire a quantity of times of reversal of a next hop chaining counter in the security key context. It should be noted that, technical solutions provided in the present invention can effectively improve reliability of a path switch during carrier aggregation between base stations.