SGSN Root Key Derivation for LTE Security Negotiation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is no method in prior art for negotiating security capabilities during the tracking area update (TAU) procedure between heterogeneous wireless networks, leading to insecurity in interactions between user equipment (UE) and the network when moving from 2G/3G to LTE networks.
Innovation Solution
A communication method and system where the Serving GPRS Support Node (SGSN) receives a context request from the Mobility Management Entity (MME), calculates a root key, and sends it back to derive NAS protection keys, enabling secure negotiation of security algorithms and keys between the UE and the LTE network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the UE moves from 2G/3G network to LTE network and performs TAU procedure, then the UE can access the LTE network, but the security capability negotiation cannot be performed resulting in security vulnerability
Solution Approach 1:
The SGSN performs preliminary key derivation and security capability preparation before the UE arrives at the LTE network. The SGSN derives the root key from the authentication vector-related key stored in the HSS, and prepares security capability information in advance. This preliminary action ensures that when the TAU procedure is initiated, the security negotiation can immediately proceed without interruption or vulnerability.
Solution Approach 2:
The SGSN acts as an intermediary between the HSS and the MME during the TAU procedure. It receives the context request from the MME, retrieves the authentication vector-related key from the HSS, derives the root key, and forwards the necessary security information to the MME. This intermediary role enables security capability negotiation across heterogeneous networks by bridging the legacy 2G/3G authentication infrastructure with the LTE security requirements.
2Ease of operation
If the entity performing security capability negotiation changes from SGSN to MME during TAU, then the TAU procedure can be completed, but the security capabilities may be inconsistent leading to security risks
Solution Approach 1:
The SGSN provides feedback to the MME about the UE's security capabilities and the derived root key information. This feedback mechanism ensures that the MME can properly configure security parameters based on the UE's authentication status and the network's security policies. The feedback loop maintains security capability consistency by ensuring both the SGSN and MME have aligned understanding of the UE's security posture throughout the TAU procedure.
Data Source
AI summary
A communication method includes receiving by a SGSN a context request message from a mobility management entity (MME), obtaining by the SGSN an authentication vector-related key, and calculating by the SGSN a root key according to the authentication vector-related key. In addition, the method further includes sending by the SGSN a context response message including the root key to the MME, wherein the MME derives a NAS protection key according to the root key.


