UMTS Key Derivation from LTE Root Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In UMTS-LTE hybrid networking scenarios with an eNB as an anchor point, the UMTS system lacks a security key, leading to unprotected data transmission and vulnerability to attacks, as it cannot perform authentication with the core network to generate a security key.

Innovation Solution

Deriving UMTS integrity and cipher keys using a root key and count value or random number from the LTE system, enabling secure communication by implementing these keys within the UMTS system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If UMTS system uses its own security protocol layer for protection, then security protection is provided, but the system cannot generate security keys in UL Boosting scenario with eNB as anchor point

Engineering Contradiction:
Improvesecurity protectionVSAvoidkey generation capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The LTE security key (Kasme) is made multi-functional by using it to derive both LTE security parameters and UMTS security keys (CK and IK). This allows a single key to serve multiple security purposes across different radio access technologies, enabling the UMTS system to generate security keys in the UL Boosting scenario without requiring a separate UMTS core network authentication.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

A key derivation function acts as an intermediary mechanism that transforms the LTE root key into UMTS security keys. This mediator enables the transition from LTE security context to UMTS security context, allowing secure UMTS communication to be established using LTE-derived keys when no UMTS core network is available.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If UMTS system derives security keys from LTE system, then security keys are available for UMTS, but the system architecture becomes more complex

Engineering Contradiction:
Improvesecurity key availabilityVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The LTE security key (Kasme) is established in advance during LTE authentication before UMTS communication is needed. This preliminary key establishment enables subsequent UMTS key derivation without requiring additional authentication procedures, simplifying the overall process despite the cross-system key derivation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security key parameters are transformed from LTE format (Kasme) to UMTS format (CK and IK) through a standardized key derivation function. This parameter transformation maintains security while adapting to different system requirements, adding minimal complexity through a well-defined mathematical transformation.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2663107B1Key generating method and apparatus
Publication Date: 2019.11.20 HUAWEI TECH CO LTD
  • EP2663107B1 patent drawingFigure 1
  • EP2663107B1 patent drawingFigure 2
  • EP2663107B1 patent drawingFigure 3

AI summary

A method and a device for key generation are disclosed in embodiments of the present invention. The method for key generation is applied to a UMTS-LTE resource convergence scenario that has a base station as an anchor point, and includes: deriving, according to a root key and a count value of an LTE system, or according to a random number and an LTE system root key, a UMTS integrity key and cipher key, and sending the UMTS integrity key and cipher key to a UMTS control node, so that the UMTS control node implements cipher and integrity protection by using the UMTS integrity key and cipher key. The embodiments of the present invention enable the derivation of the UMTS integrity key and cipher key in a UMTS-LTE resource convergence scenario that has a base station as an anchor point, enable a user equipment to communicate securely through a UMTS, and further improve security of data transmitted in the UMTS.