SGSN Root Key Derivation for LTE Security Negotiation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is no method in prior art for negotiating security capabilities during the tracking area update (TAU) procedure between heterogeneous wireless networks, leading to insecurity in interactions between user equipment (UE) and the network when moving from 2G/3G to LTE networks.

Innovation Solution

A communication method and system where the Serving GPRS Support Node (SGSN) receives a context request from the Mobility Management Entity (MME), calculates a root key, and sends it back to derive NAS protection keys, enabling secure negotiation of security algorithms and keys between the UE and the LTE network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the UE moves from 2G/3G network to LTE network and performs TAU procedure, then the UE can access the LTE network, but the security capability negotiation cannot be performed resulting in security vulnerability

Engineering Contradiction:
Improvesecurity of interactionVSAvoidsecurity capability negotiation between heterogeneous networks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The SGSN performs preliminary key derivation and security capability preparation before the UE arrives at the LTE network. The SGSN derives the root key from the authentication vector-related key stored in the HSS, and prepares security capability information in advance. This preliminary action ensures that when the TAU procedure is initiated, the security negotiation can immediately proceed without interruption or vulnerability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The SGSN acts as an intermediary between the HSS and the MME during the TAU procedure. It receives the context request from the MME, retrieves the authentication vector-related key from the HSS, derives the root key, and forwards the necessary security information to the MME. This intermediary role enables security capability negotiation across heterogeneous networks by bridging the legacy 2G/3G authentication infrastructure with the LTE security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the entity performing security capability negotiation changes from SGSN to MME during TAU, then the TAU procedure can be completed, but the security capabilities may be inconsistent leading to security risks

Engineering Contradiction:
ImproveTAU procedure completionVSAvoidsecurity capability consistency
Core Design Contradiction:
Ease of operationVSStability of the object's composition

Solution Approach 1:

The SGSN provides feedback to the MME about the UE's security capabilities and the derived root key information. This feedback mechanism ensures that the MME can properly configure security parameters based on the UE's authentication status and the network's security policies. The feedback loop maintains security capability consistency by ensuring both the SGSN and MME have aligned understanding of the UE's security posture throughout the TAU procedure.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10595198B2Communication method and device
Publication Date: 2020.03.17 HUAWEI TECH CO LTD
  • US10595198B2 patent drawing
  • US10595198B2 patent drawing
  • US10595198B2 patent drawing

AI summary

A communication method includes receiving by a SGSN a context request message from a mobility management entity (MME), obtaining by the SGSN an authentication vector-related key, and calculating by the SGSN a root key according to the authentication vector-related key. In addition, the method further includes sending by the SGSN a context response message including the root key to the MME, wherein the MME derives a NAS protection key according to the root key.