UE Handover Failure Security Key Derivation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless communication systems, existing methods fail to efficiently manage connection failures during handover, leading to integrity issues when a user equipment (UE) falls back to a source network after failing to connect to a target network, as the same security key cannot be reused.

Innovation Solution

A method where a user equipment (UE) receives a handover command with security information, establishes a connection with a second network, derives a new security key for the first network upon detecting a connection failure, and performs PDCP re-establishment for radio bearers, ensuring a new security key is used for the source network to prevent integrity failures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the UE uses the same security key for the source network after handover failure, then the UE can maintain connection with the source network, but integrity failures occur in the source network

Engineering Contradiction:
Improveconnection reliabilityVSAvoidintegrity failure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the security key parameter from its original value to a newly derived security key when handover fails and the UE returns to the source network. This parameter change prevents integrity failures while maintaining connection reliability, as the new security key ensures data integrity protection is properly applied.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent performs preliminary action by deriving a new security key in advance before the UE re-establishes communication with the source network after handover failure. This preliminary key derivation ensures that integrity protection is already in place before data transmission resumes, preventing integrity failures.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the UE derives a new security key for the source network after handover failure, then integrity failures are prevented, but additional processing time and complexity are introduced

Engineering Contradiction:
Improveintegrity protectionVSAvoidsecurity key management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by using the same security key derivation mechanism for both handover scenarios and handover failure recovery scenarios. The UE derives security keys using a unified approach whether transitioning to a target network or returning to the source network, simplifying the overall security key management while ensuring integrity protection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If the UE performs PDCP re-establishment with a new security key, then communication security is maintained, but communication delay increases

Engineering Contradiction:
Improvecommunication securityVSAvoidhandover recovery time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary action by deriving the new security key as soon as handover failure is detected, before the UE needs to re-establish communication with the source network. This preliminary key derivation minimizes the time the UE spends without secure communication capability, reducing the overall delay while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11363662B2Method and apparatus for reporting a connection failure with a target network during handover in a wireless communication system
Publication Date: 2022.06.14 LG ELECTRONICS INC
  • US11363662B2 patent drawing
  • US11363662B2 patent drawing
  • US11363662B2 patent drawing

AI summary

The present invention relates to a method for receiving packets by a user equipment (UE) in a wireless communication system. In particular, the method includes receiving a handover command including security information; establishing a connection with a second network; based on detecting a connection failure with the second network, deriving a security key for a first network based on the security information; performing a PDCP re-establishment for one or more radio bearers of the first network based on the security key for the first network; and reporting, to the first network, the connection failure with the second network.