UE Security Key Management for Seamless Handover

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In telecommunications networks, particularly in LTE environments, UE devices face challenges in managing authentication keys across multiple security contexts, leading to potential key collisions and authentication failures during handovers between different access technologies like LTE, GSM, and UMTS.

Innovation Solution

A method and system for managing security key architecture in UE devices, which involves generating and storing authentication vectors in context-specific elementary files on a removable SIM or non-volatile memory, ensuring that keys are properly stored and used in the correct security context, preventing key collisions and ensuring seamless handovers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If authentication keys are stored in a single location for multiple security contexts, then storage is simplified, but key collisions and authentication failures occur during handovers

Engineering Contradiction:
Improvekey management complexityVSAvoidauthentication reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the storage location for authentication keys by creating context-specific elementary files (EF) on the SIM card. Each security context (e.g., LTE, GSM, UMTS) has its own dedicated EF where authentication vectors are stored. This segmentation prevents key collisions between different security contexts while maintaining organized and manageable storage structures.

Inventive Principle:
Principle #1Segmentation

2Reliability

If context-specific elementary files are created on SIM card, then key collisions are prevented, but device complexity and storage management become more complex

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidstorage management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal key management mechanism that handles multiple security contexts through a standardized process. The system uses a common approach for creating context-specific EF files, managing authentication vectors, and performing handovers across different access technologies (LTE, GSM, UMTS). This universal mechanism reduces the perceived complexity by providing consistent behavior despite the segmented storage structure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If authentication vectors are stored in multiple locations, then handover between access technologies is seamless, but storage space and management overhead increase

Engineering Contradiction:
Improvehandover capabilityVSAvoidstorage space
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent applies preliminary action by pre-creating context-specific elementary files on the SIM card during initial authentication or device setup. This allows authentication vectors to be immediately stored in the appropriate location when handover is needed, eliminating the need for dynamic file creation or key transfer during the actual handover process. The preliminary organization of storage structures enables seamless handover without increasing runtime storage overhead.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2486741B1System and method for managing security keys for multiple security contexts of a wireless user device to handover communications in a network
Publication Date: 2019.07.24 BLACKBERRY LTD
  • EP2486741B1 patent drawingFigure 1
  • EP2486741B1 patent drawingFigure 2
  • EP2486741B1 patent drawingFigure 3A~3B

AI summary

A scheme for managing security key architecture in a network environment where a user equipment (UE) device can engage in multiple security contexts depending on the access technology. In one embodiment, when multiple security contexts are engaged and different sets of authentication vectors are created, an adapter component of the UE device manages potential interference that may be caused among the different sets of the authentication vectors as to where they are stored and which authentication vectors are used for service handovers.