Network Security Parameter Synchronization During Handover
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network security desynchronization occurs when user terminals hand over between different access networks, leading to failure in accessing the network due to mismatched security context parameters, particularly in scenarios involving 2G, 3G, and LTE systems, where security parameter structures and protection levels differ.
Innovation Solution
A method and device for user terminals to perform network handovers by generating new derived keys through key derivation in the new network and modifying security parameters stored in the USIM, including obtaining a new KSI from the original network, modifying it, and notifying the terminal to ensure synchronization across networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If security context parameters are reused during handover between different access networks, then handover efficiency is improved, but security desynchronization occurs leading to access failures
Solution Approach 1:
The patent applies preliminary action by modifying the START value before handover occurs. When the START value reaches a threshold, the system proactively resets it to 0 and triggers a new authentication and key agreement process. This prevents security desynchronization from occurring in the first place, ensuring that security parameters remain synchronized between the terminal and network during handover operations.
Solution Approach 2:
The patent implements feedback mechanisms where the terminal and network continuously monitor and compare security context parameters including KSI and START values. When parameters are reused during handover, the system verifies synchronization status and triggers re-authentication if desynchronization is detected, ensuring security parameters remain consistent across different access networks.
2Adaptability or versatility
If different security parameter structures are used in heterogeneous access networks, then network compatibility is improved, but security context reuse becomes complex
Solution Approach 1:
The patent applies universality by designing a unified security parameter management mechanism that works across heterogeneous access networks (2G, 3G, LTE). The START value reset mechanism and KSI comparison logic are implemented in a network-agnostic manner, allowing the same security context parameters to be reused across different radio access technologies while maintaining consistent security policies and synchronization procedures.
Data Source
Figure 1~2
Figure 3~4
Figure 5~6
AI summary
A method and a device for avoiding network security desynchronization are provided. The method includes: processing only security parameter in a user terminal (a Universal Subscriber Identity Module (USIM) part) at an appropriate time, or processing security parameter in both the user terminal (a Mobile Equipment (ME) part) and the network when a network handover of the user terminal is performed. By modifying security parameter at an appropriate time, the failure of a UE to access a network due to the security parameter desynchronization is effectively avoided, and network availability and security in handover-related scenarios are improved.