Terminal Key Derivation for Secure Secondary-Node Migration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current communication technologies face security risks in dual-connectivity scenarios due to insecure connections between communication apparatuses and secondary nodes.

Innovation Solution

A method and apparatus for deriving and managing distinct keys based on count values to establish secure connections between a terminal device and secondary nodes, ensuring key isolation and improved security performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single key is used for communication with multiple secondary nodes, then device complexity is reduced, but security performance deteriorates

Engineering Contradiction:
Improvekey management complexityVSAvoidcommunication security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the communication security by deriving different keys (first key, second key, third key) for different secondary nodes and different communication scenarios. Each key is specifically tied to a particular secondary node or migration scenario, ensuring that compromise of one key does not affect security with other nodes. This segmentation resolves the contradiction by maintaining security through key differentiation while keeping the key derivation mechanism unified and manageable.

Inventive Principle:
Principle #1Segmentation

2Reliability

If different keys are derived for different secondary nodes, then communication security is improved, but device complexity increases

Engineering Contradiction:
Improvecommunication securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-configuring multiple count values (first count value, second count value, third count value) and their corresponding keys before communication with secondary nodes. The terminal device and network side device both store these pre-derived keys, eliminating the need for complex real-time key generation and synchronization during communication establishment. This preliminary key derivation and distribution simplifies the overall key management complexity while maintaining high security standards.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250227797A1Communication method and apparatus
Publication Date: 2025.07.10 HUAWEI TECH CO LTD
  • US20250227797A1 patent drawing
  • US20250227797A1 patent drawing
  • US20250227797A1 patent drawing

AI summary

This application provides a communication method and apparatus. The method includes: A first terminal device derives a first key based on a first count value, where the first key is used to protect communication security between the first terminal device and a first secondary node after the first terminal device accesses the first secondary node. The first terminal device stores a second count value, where the second count value is equal to the first count value plus n, the second count value is used to derive a second key, and the second key is used to protect communication security between the first terminal device and a second secondary node when the first terminal device migrates from the first secondary node to the second secondary node.