Network Security Parameter Synchronization During Handover

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network security desynchronization occurs when user terminals hand over between different access networks, leading to failure in accessing the network due to mismatched security context parameters, particularly in scenarios involving 2G, 3G, and LTE systems, where security parameter structures and protection levels differ.

Innovation Solution

A method and device for user terminals to perform network handovers by generating new derived keys through key derivation in the new network and modifying security parameters stored in the USIM, including obtaining a new KSI from the original network, modifying it, and notifying the terminal to ensure synchronization across networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If security context parameters are reused during handover between different access networks, then handover efficiency is improved, but security desynchronization occurs leading to access failures

Engineering Contradiction:
Improvehandover efficiencyVSAvoidsecurity synchronization
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by modifying the START value before handover occurs. When the START value reaches a threshold, the system proactively resets it to 0 and triggers a new authentication and key agreement process. This prevents security desynchronization from occurring in the first place, ensuring that security parameters remain synchronized between the terminal and network during handover operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the terminal and network continuously monitor and compare security context parameters including KSI and START values. When parameters are reused during handover, the system verifies synchronization status and triggers re-authentication if desynchronization is detected, ensuring security parameters remain consistent across different access networks.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If different security parameter structures are used in heterogeneous access networks, then network compatibility is improved, but security context reuse becomes complex

Engineering Contradiction:
Improvenetwork compatibilityVSAvoidsecurity parameter management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing a unified security parameter management mechanism that works across heterogeneous access networks (2G, 3G, LTE). The START value reset mechanism and KSI comparison logic are implemented in a network-agnostic manner, allowing the same security context parameters to be reused across different radio access technologies while maintaining consistent security policies and synchronization procedures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3197191B1Method and apparatuses for avoiding network security desynchronization
Publication Date: 2019.12.18 HUAWEI TECH CO LTD
  • EP3197191B1 patent drawingFigure 1~2
  • EP3197191B1 patent drawingFigure 3~4
  • EP3197191B1 patent drawingFigure 5~6

AI summary

A method and a device for avoiding network security desynchronization are provided. The method includes: processing only security parameter in a user terminal (a Universal Subscriber Identity Module (USIM) part) at an appropriate time, or processing security parameter in both the user terminal (a Mobile Equipment (ME) part) and the network when a network handover of the user terminal is performed. By modifying security parameter at an appropriate time, the failure of a UE to access a network due to the security parameter desynchronization is effectively avoided, and network availability and security in handover-related scenarios are improved.