Handover Security Parameter Transfer Between UTRA and E-UTRA
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In mobile communication systems combining UTRA and E-UTRA radio access networks, there is a lack of clear definition on how to transfer security-related information during handovers between cells controlled by different radio base stations, leading to potential security issues and communication disruptions.
Innovation Solution
A method and system for handover procedures that involve transmitting and selecting appropriate security processing parameters and algorithms across switching centers and radio base stations, ensuring seamless security processing in both UTRA and E-UTRA schemes, including the use of transparent containers to manage security algorithms and parameters during handovers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security processing parameters are transferred during handover between UTRA and E-UTRA schemes, then communication security is maintained, but the complexity of the handover procedure increases
Solution Approach 1:
The source eNB performs security processing parameter generation and selection before the handover is executed. The target eNB receives pre-configured security parameters in the handover request message, allowing it to immediately activate security processing without delay. This preliminary preparation resolves the contradiction by maintaining security reliability while reducing the operational complexity during the actual handover execution.
Solution Approach 2:
The source eNB acts as an intermediary that bridges the UTRA and E-UTRA security domains. It translates and converts security parameters from the UTRA format to E-UTRA format, then forwards them to the target eNB. This intermediary role simplifies the handover procedure by handling the complex parameter conversion centrally, rather than requiring the target eNB to perform complex translations, thus maintaining security while reducing procedural complexity.
2Adaptability or versatility
If different security processing algorithms are used in UTRA and E-UTRA schemes, then each scheme can use optimized algorithms, but the difficulty of managing security parameters during handover increases
Solution Approach 1:
The invention systematically changes security parameters including algorithm selection, key material, and configuration settings when transitioning between UTRA and E-UTRA schemes. The source eNB identifies the appropriate E-UTRA security parameters based on the target cell's requirements and converts them from UTRA parameters. This structured parameter transformation approach enables each scheme to use its optimized algorithms while making parameter management tractable through systematic conversion rules.
Solution Approach 2:
The security parameter management is segmented into distinct components: algorithm selection, key material generation, and configuration parameter setting. Each component is handled separately and systematically during the handover process. The source eNB processes each security parameter component independently, converting and transmitting them through the handover procedure. This segmentation reduces the overall difficulty by breaking down the complex parameter management into manageable, systematic steps.
Data Source
Figure 1~2
Figure 3~4
Figure 5
AI summary
In a procedure for a mobile station (UE) to perform handover from a cell under the control of a radio base station (NB) of an UTRAN scheme to a cell under the control of a radio base station (eNB) of an E-UTRA scheme, a switching center (MME) of the E-UTRA scheme receives, from and the radio base station (eNB) of the E-UTRA scheme, a handover request acknowledge message including a transparent container including a security algorithm of an AS used in a communication between the mobile station (UE) and the radio base station (eNB) of the E-UTRA scheme; and the switching center (MME) of the E-UTRA scheme transmits, to a switching center (SGSN) of the UTRA scheme, a NAS PDU including the transparent container, a security algorithm of a NAS and a security processing parameter of the NAS.