Secondary Node Security Key Synchronization in 5G Dual Connectivity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In dual connectivity scenarios, there is an interruption of service due to the failure of UE and SN to switch over from old to new security keys during inter-MN handovers in 5G cellular networks, leading to temporary loss of encryption support.

Innovation Solution

The SN applies a new security key only after verifying that the UE possesses the matching key, through a key alignment event such as completion of a channel access procedure or receiving specific messages, ensuring synchronized security key alignment between the UE and SN.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If the SN switches to a new security key immediately after receiving it from the new MN, then security update speed is improved, but service interruption occurs due to key misalignment between UE and SN

Engineering Contradiction:
Improvesecurity key update speedVSAvoidservice continuity
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The SN performs preliminary actions to prepare for the security key switch by suspending downlink transmissions before the actual key switch occurs. This ensures that no data is transmitted with mismatched keys, preventing service interruption while maintaining security. The suspension is lifted only after confirming the UE has also switched to the new key.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses feedback mechanisms to detect when the UE has successfully switched to the new security key. The SN monitors for specific events (such as successful channel access or receipt of confirmation messages) that indicate the UE's key switch status. Only after receiving this feedback does the SN resume normal transmissions, ensuring key alignment between UE and SN.

Inventive Principle:
Principle #23Feedback

2Reliability

If the SN waits for key alignment events before applying the new security key, then service continuity is maintained, but security update speed decreases

Engineering Contradiction:
Improveservice continuityVSAvoidsecurity key update speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The SN prepares in advance by suspending downlink transmissions before the actual key switch occurs. This preliminary suspension prevents any data transmission with potentially mismatched keys, ensuring service continuity while the key switch process completes. The suspension duration is minimized by efficiently detecting key alignment events.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The SN actively monitors for feedback events that indicate the UE has successfully switched to the new security key. These events may include successful channel access procedures, receipt of specific messages from the UE, or other synchronization indicators. Upon detecting such feedback, the SN immediately resumes transmissions, minimizing the delay caused by waiting for key alignment.

Inventive Principle:
Principle #23Feedback

3Manufacturing precision

If the SN suspends downlink transmissions during key transition, then encryption alignment is ensured, but productivity decreases due to communication pause

Engineering Contradiction:
Improveencryption alignment precisionVSAvoidcommunication throughput
Core Design Contradiction:
Manufacturing precisionVSProductivity

Solution Approach 1:

The SN suspends downlink transmissions as a preliminary measure before the security key switch is complete. This ensures that no data is transmitted with mismatched encryption keys, maintaining precise encryption alignment. The suspension is time-limited and immediately lifted upon detecting that the UE has also switched to the new key, minimizing the impact on productivity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The SN uses feedback mechanisms to detect when the UE has successfully switched to the new security key. Upon receiving feedback indicating successful key alignment (such as successful channel access or confirmation messages), the SN immediately resumes downlink transmissions. This feedback-driven approach ensures precise encryption alignment while minimizing the duration of the communication pause, thus reducing the impact on productivity.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20220345883A1Security key updates in dual connectivity
Publication Date: 2022.10.27 GOOGLE LLC
  • US20220345883A1 patent drawing
  • US20220345883A1 patent drawing
  • US20220345883A1 patent drawing

AI summary

A base station security communicates with a UE operating as an SN in dual connectivity of the UE with a first MN and the SN. The base station communicates with the UE over a radio interface using a first security key (802). The base station then receives, from a second MN, a first message including data for obtaining a second security key for communicating with the UE (804) and suspends application of the second security key to downlink traffic to the UE until a second message is received (806). In response to receiving the second message, base station communicates with the UE over the radio interface using the second security key (808).