Session Management Device Handover Key Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G networks, ensuring secure data transmission during user equipment (UE) handovers is challenging as existing methods lack an efficient mechanism to generate and manage shared keys for end-to-end protection across different networks.

Innovation Solution

A network handover protection method that involves a session management device obtaining a target security policy and using it to generate or obtain a second shared key, which is then sent to the UE or target gateway for secure data transmission, ensuring continuity of end-to-end protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a new shared key is generated when UE establishes a new session to target UP-GW, then end-to-end protection is maintained, but key management complexity increases during network handover

Engineering Contradiction:
Improveend-to-end protectionVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The session management device performs preliminary actions by obtaining the target security policy and generating the second shared key before the UE actually establishes the new session in the target network. This advance preparation eliminates the complexity of key generation during the handover process, as the key is already ready when the session needs to be established.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The session management device acts as an intermediary that handles the complex key management operations between the UE and target UP-GW. By centralizing the key generation and management functions in the session management device, the patent simplifies the overall system architecture while maintaining end-to-end protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If shared key generation is performed during network handover, then security continuity is ensured, but handover time increases

Engineering Contradiction:
Improvesecurity continuityVSAvoidhandover time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by obtaining the target security policy and generating the second shared key before the actual session establishment in the target network. This advance key preparation ensures that when the UE establishes the new session, the shared key is already ready, eliminating delays that would otherwise occur during key generation and ensuring both security continuity and efficient handover.

Inventive Principle:
Principle #10Preliminary action

3Ease of manufacture

If existing key management methods are used during handover, then implementation simplicity is maintained, but security protection during handover is insufficient

Engineering Contradiction:
Improveimplementation simplicityVSAvoidsecurity protection
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent changes the key parameter by introducing a second shared key specifically for the target network session, distinct from the first shared key used in the source network. This parameter change enables the system to maintain security protection during handover while keeping the implementation simple, as the new key is generated using the same cryptographic principles but adapted for the target network's security requirements.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10959091B2Network handover protection method, related device, and system
Publication Date: 2021.03.23 HUAWEI TECH CO LTD
  • US10959091B2 patent drawing
  • US10959091B2 patent drawing
  • US10959091B2 patent drawing

AI summary

A method includes: receiving, by a session management device, a path switching request used to request to hand over user equipment UE from a source network to a target network; obtaining a target security policy based on the path switching request, and obtaining a second shared key generated based on a first shared key and the target security policy, and sending the second shared key to a target gateway; and sending, by the session management device, the second shared key to the UE; or sending the target security policy to the UE, so that the UE generates the second shared key based on the first shared key and the target security policy, where the second shared key is used to perform end-to-end protection on secure data transmission between the UE and the target gateway.