Security Key Generation for RRC Inactive State Resumption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies do not describe how to generate security keys for data radio bearers when a user equipment (UE) transitions to an RRC inactive state and resumes a connection, particularly in dual connectivity scenarios where data is transmitted between master and secondary network nodes.

Innovation Solution

The UE generates a new security key (K-sn) using a previously derived key (K-mn) and a Next Hop Chaining Counter (NCC) value, which is indicated by the network node, to ensure secure data transmission during connection resume and data transmission in the RRC inactive state, using either a horizontal or vertical derivation method based on the NCC values.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If the UE uses the existing security key (K-mn) for data transmission in RRC inactive state, then the device complexity is reduced, but the security reliability deteriorates because the key may not be sufficient for secure communication during connection resume

Engineering Contradiction:
Improvesecurity key management complexityVSAvoidcommunication security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The network node pre-indicates the NCC value to the UE before the UE transitions to RRC inactive state. This preliminary action enables the UE to derive the appropriate security key (K-sn) in advance or during connection resume, ensuring security reliability without adding complex real-time key management operations during data transmission in inactive state.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the UE derives a new security key (K-sn) using NCC value during connection resume, then the communication security is improved, but the device complexity increases due to additional key derivation operations

Engineering Contradiction:
Improvecommunication securityVSAvoidkey derivation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The NCC value is indicated by the network node in advance (in RRC release message or system information), allowing the UE to have the necessary parameter ready before connection resume. This reduces the complexity burden during the actual key derivation process by having the input parameter pre-available.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces the NCC counter value as a new parameter that changes with each security context. This parameter enables the UE to distinguish between different security contexts (horizontal derivation with same NCC vs. vertical derivation with different NCC) and derive appropriate keys using standardized algorithms, making the complexity manageable through parameter differentiation.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If the network node indicates the NCC value in advance, then the security key generation reliability is improved, but the loss of information increases due to additional signaling requirements

Engineering Contradiction:
Improvesecurity key generationVSAvoidsignaling overhead
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The NCC value indication mechanism is designed to serve multiple purposes: it provides the counter value for key derivation, indicates the security context type (horizontal or vertical derivation), and enables the network to control security key generation. This multi-functionality reduces the need for separate signaling messages, thereby minimizing additional signaling overhead while improving security key generation reliability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11632245B2Security key generation techniques
Publication Date: 2023.04.18 ZTE CORP
  • US11632245B2 patent drawing
  • US11632245B2 patent drawing
  • US11632245B2 patent drawing

AI summary

Techniques are described to generate a first security key when a user equipment operating in an inactive state initiates a data transmission or a procedure to resume network connection. The first security key is generated based on a second security key associated with a first network node and a counter value, and the first security key is associated with a second network node and is used to generate user plane security keys to transmit data to or to receive data from one or more network nodes.