Method and system to enable secure communication for inter-eNB transmission
The embodiments herein provide a method and system for creating a secure connection for a User Equipment (UE) in a wireless network including a UE, carrier aggregated with at least one first serving frequency served by a first eNB and at least one second serving frequency served by a second eNB. A unique non-repetitive security base key associated with the second eNB is generated using a freshness parameter and security key associated with the first eNB. The use of a different freshness parameter for each security base key derivation avoids key stream repetition. Further, a user plane encryption key is derived based on the generated unique non-repetitive security base key associated with the second eNB for encrypting data transfer over at least one data radio bearer.
1. A method by a first base station in a mobile communication system, the method comprising:
generating a first security key associated with a second base station using a secondary cell group (SCG) counter value and a base security key of the first base station, data between a terminal and the first base station being encrypted based on the base security key received from a mobility management entity (MME); and
transmitting the first security key to the second base station;
wherein the first security key is used to generate a second security key, which is used for encrypting data between the terminal and the second base station,
wherein the SCG counter value is used to avoid key repetition, and
wherein at least one cell associated with the first base station and at least one cell associated with the second base station are aggregated for the terminal.
2. The method of claim 1 , further comprising:
transmitting a radio resource control (RRC) connection reconfiguration message including the SCG counter value to the terminal over a RRC signaling.
3. The method of claim 1 , further comprising:
maintaining the SCG counter value for a duration of a current access stratum (AS) security context.
4. The method of claim 1 , wherein the base security key is refreshed before the SCG counter value wraps around.
5. A method by a second base station in a mobile communication system, the method comprising:
receiving a first security key associated with the second base station generated by using a secondary cell group (SCG) counter value and a base security key of a first base station, data between a terminal and the first base station being encrypted based on the base security key transmitted from a mobility management entity (MME); and
generating a second security key using the first security key,
wherein the first security key is used to generate the second security key, which is used for encrypting data between the terminal and the second base station,
wherein the SCG counter value is used to avoid key repetition, and
wherein at least one cell associated with the first base station and at least one cell associated with the second base station are aggregated for the terminal.
6. The method of claim 5 , wherein a radio resource control (RRC) connection reconfiguration message including the SCG counter value is transmitted from the first base station to the terminal over a RRC signaling.
7. The method of claim 5 , wherein the security key is refreshed before the SCG counter value wraps around.
8. A first base station in a mobile communication system, the first base station comprising:
a transceiver; and
at least one processor configured to:
generate a first security key associated with a second base station using a secondary cell group (SCG) counter value and a base security key of the first base station, data between a terminal and the first base station being encrypted based on the base security key received from a mobility management entity (MME), and
transmit, via the transceiver, the first security key to the second base station,
wherein the first security key is used to generate a second security key, which is used for encrypting data between the terminal and the second base station,
wherein the SCG counter value is used to avoid key repetition, and
wherein at least one cell associated with the first base station and at least one cell associated with the second base station are aggregated for the terminal.
9. The first base station of claim 8 , wherein the at least one processor is further configured to transmit a radio resource control (RRC) connection reconfiguration message including the SCG counter value to the terminal over a RRC signaling.
10. The first base station of claim 8 , wherein the at least one processor is further configured to maintain the SCG counter value for a duration of a current access stratum (AS) security context.
11. The first base station of claim 8 , wherein the base security key is refreshed before the SCG counter value wraps around.
12. A second base station in a mobile communication system supporting a dual connectivity, the second base station comprising:
a transceiver; and
at least one processor configured to:
receive, via the transceiver, a first security key associated with the second base station generated by using a secondary cell group (SCG) counter value and a security key of the first base station, data between a terminal and the first base station being encrypted based on the base security key transmitted from a mobility management entity (MME), and
generate a second security key using the first security key,
wherein the first security key is used to generate the second security key, which is used for encrypting data between a terminal and the second base station,
wherein the SCG counter value is used to avoid key repetition, and
wherein at least one cell associated with the first base station and at least one cell associated with the second base station are aggregated for the terminal.
13. The second base station of claim 12 , wherein a radio resource control (RRC) connection reconfiguration message including the SCG counter value is transmitted from the first base station to the terminal over a RRC signaling.
14. The second base station of claim 12 , wherein the security key is refreshed before the SCG counter value wraps around.