Terminal Key Derivation for Secure Secondary-Node Migration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current communication technologies face security risks in dual-connectivity scenarios due to insecure connections between communication apparatuses and secondary nodes.
Innovation Solution
A method and apparatus for deriving and managing distinct keys based on count values to establish secure connections between a terminal device and secondary nodes, ensuring key isolation and improved security performance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a single key is used for communication with multiple secondary nodes, then device complexity is reduced, but security performance deteriorates
Solution Approach 1:
The patent segments the communication security by deriving different keys (first key, second key, third key) for different secondary nodes and different communication scenarios. Each key is specifically tied to a particular secondary node or migration scenario, ensuring that compromise of one key does not affect security with other nodes. This segmentation resolves the contradiction by maintaining security through key differentiation while keeping the key derivation mechanism unified and manageable.
2Reliability
If different keys are derived for different secondary nodes, then communication security is improved, but device complexity increases
Solution Approach 1:
The patent implements preliminary action by pre-configuring multiple count values (first count value, second count value, third count value) and their corresponding keys before communication with secondary nodes. The terminal device and network side device both store these pre-derived keys, eliminating the need for complex real-time key generation and synchronization during communication establishment. This preliminary key derivation and distribution simplifies the overall key management complexity while maintaining high security standards.
Data Source
AI summary
This application provides a communication method and apparatus. The method includes: A first terminal device derives a first key based on a first count value, where the first key is used to protect communication security between the first terminal device and a first secondary node after the first terminal device accesses the first secondary node. The first terminal device stores a second count value, where the second count value is equal to the first count value plus n, the second count value is used to derive a second key, and the second key is used to protect communication security between the first terminal device and a second secondary node when the first terminal device migrates from the first secondary node to the second secondary node.


