Unified Security Key Derivation for Wireless Handover

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication systems face delays and complexity in handover procedures due to the derivation of security keys, particularly when transitioning between network entities, as they often require sharing and rederivation of higher-level keys, which can complicate the process and delay handovers.

Innovation Solution

The implementation of an intermediate key, such as an AS root key, is generated based on freshness parameters and shared between network entities to facilitate secure communication, allowing for unified and efficient derivation of base station keys during handovers, reducing the need for sharing higher-level keys and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security key derivation methods are used during handover, then security is maintained through higher-level key sharing, but handover delays occur due to complex key rederivation and signaling between network entities

Engineering Contradiction:
ImprovesecurityVSAvoidhandover delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the security key derivation process by introducing an intermediate key (KgNB*) that separates the higher-level AMF key (KAMF) from the base station key (KgNB). This segmentation allows the target base station to derive KgNB directly from the intermediate key without requiring signaling with the target AMF, thus reducing handover delay while maintaining security through the chained key derivation structure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediate key (KgNB*) as a mediator between the AMF key and the base station key. This intermediate key enables the target base station to perform local key derivation without direct communication with the target AMF, acting as a bridge that eliminates the need for real-time AMF involvement in the handover key derivation process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If higher-level keys are shared and rederived between network entities, then security is maintained, but device complexity increases due to multiple key derivation functions and signaling requirements

Engineering Contradiction:
ImprovesecurityVSAvoidkey derivation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the key derivation hierarchy into distinct segments: KAMF for AMF security, KgNB* as an intermediate key, and KgNB for base station security. This segmentation simplifies the derivation process at each level by eliminating the need for cross-level signaling and complex chained derivations, reducing device complexity while preserving security through the segmented structure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The intermediate key KgNB* serves as a mediator that simplifies the key derivation process by providing a direct input to the target base station. This eliminates the need for the target base station to participate in higher-level key derivations or communicate with the target AMF for key establishment, thereby reducing the complexity of key management procedures.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If unified key derivation is implemented at target network entity, then handover efficiency improves, but signaling overhead increases due to parameter exchange between network entities

Engineering Contradiction:
Improvehandover efficiencyVSAvoidsignaling overhead
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent applies preliminary action by having the source base station generate and forward the intermediate key (KgNB*) to the target base station before the handover is completed. This preliminary key preparation eliminates the need for subsequent key derivation signaling between the target base station and target AMF, improving handover efficiency while minimizing signaling overhead.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The intermediate key KgNB* acts as a mediator that carries security information from the source side to the target side without requiring additional signaling exchanges. By embedding the intermediate key in the handover request message, the patent enables unified key derivation at the target base station while avoiding extra signaling overhead for key parameter exchange.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3659365B1Security key derivation for handover
Publication Date: 2022.12.28 QUALCOMM INC
  • EP3659365B1 patent drawingFigure 1
  • EP3659365B1 patent drawingFigure 2
  • EP3659365B1 patent drawingFigure 3

AI summary

Methods, systems, and devices for wireless communication are described that support security key derivation for handover. A network entity (e.g., an access and mobility function (AMF)) may establish an access stratum (AS) key to ensure secure communications between a user equipment (UE) and a base station. If the UE relocates to a new network entity (e.g., target network entity), the initial network entity (e.g., source network entity) may perform a handover procedure to the target network entity. In some aspects, the network entities may derive a unified AS key for the handover procedure. Additionally, the network entities may utilize one or more intermediate keys (e.g., refreshed intermediate keys) derived from, in part, respective freshness parameters for the handover procedure. The target network entity may then utilize the derived intermediate keys to derive the AS key for the handover procedure and establish communications with the UE.