UE Security Key Management for Seamless Handover
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In telecommunications networks, particularly in LTE environments, UE devices face challenges in managing authentication keys across multiple security contexts, leading to potential key collisions and authentication failures during handovers between different access technologies like LTE, GSM, and UMTS.
Innovation Solution
A method and system for managing security key architecture in UE devices, which involves generating and storing authentication vectors in context-specific elementary files on a removable SIM or non-volatile memory, ensuring that keys are properly stored and used in the correct security context, preventing key collisions and ensuring seamless handovers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If authentication keys are stored in a single location for multiple security contexts, then storage is simplified, but key collisions and authentication failures occur during handovers
Solution Approach 1:
The patent segments the storage location for authentication keys by creating context-specific elementary files (EF) on the SIM card. Each security context (e.g., LTE, GSM, UMTS) has its own dedicated EF where authentication vectors are stored. This segmentation prevents key collisions between different security contexts while maintaining organized and manageable storage structures.
2Reliability
If context-specific elementary files are created on SIM card, then key collisions are prevented, but device complexity and storage management become more complex
Solution Approach 1:
The patent implements a universal key management mechanism that handles multiple security contexts through a standardized process. The system uses a common approach for creating context-specific EF files, managing authentication vectors, and performing handovers across different access technologies (LTE, GSM, UMTS). This universal mechanism reduces the perceived complexity by providing consistent behavior despite the segmented storage structure.
3Adaptability or versatility
If authentication vectors are stored in multiple locations, then handover between access technologies is seamless, but storage space and management overhead increase
Solution Approach 1:
The patent applies preliminary action by pre-creating context-specific elementary files on the SIM card during initial authentication or device setup. This allows authentication vectors to be immediately stored in the appropriate location when handover is needed, eliminating the need for dynamic file creation or key transfer during the actual handover process. The preliminary organization of storage structures enables seamless handover without increasing runtime storage overhead.
Data Source
Figure 1
Figure 2
Figure 3A~3B
AI summary
A scheme for managing security key architecture in a network environment where a user equipment (UE) device can engage in multiple security contexts depending on the access technology. In one embodiment, when multiple security contexts are engaged and different sets of authentication vectors are created, an adapter component of the UE device manages potential interference that may be caused among the different sets of the authentication vectors as to where they are stored and which authentication vectors are used for service handovers.