You are on page 1of 3

LTE Security Keys-K, (CK,IK), KASME, KeNB,

KeNB*, NH, KNASint, KNASenc, KUPenc, KRRCint and

LTE
Security Length Derived
Key Function or Size From Basic Description

Master Base Key for Secret key stored permanently in USIM


K GSM/UMTS/EPS 128 - and AuC

Cipher key and Pair of Keys derived in AuC and USIM


(CK,IK) Integrity Key 128 'K' Key during AKA run.

MME (ASME) Base Intermediate key derived in HSS/UE from


KASME / Intermediate Key 256 CK,IK (CK,IK) using AKA.

Intermediate Key derived in MME/UE


from KASME when UE transits to ECM
KASME , CONNECTED STATE or by UE and
K-eNB eNB Base Key 256 KeNB* target eNB from KeNB* during handover

Intermediate Key derived in source eNB


and UE during handover when
performing horizontal ( KeNB) or vertical
eNB handover KeNB(H) , Key(NH) derivation. Used at target eNB
KeNB* transition Key 256 NH(V) to derive KeNB

Intermediate key derived in MME and


UE used to provide forward security and
NH Next Hop 256 KeNB forwarded to eNB via S1-MME interface.

KRRCenc
Integrity key for 256 (128 Integrity key for protection of NAS data
KNASint NAS signalling LSB) KASME derived in MME/UE

Encryption Key for 256(128 Encryption key for protection of NAS


KNASenc NAS signalling LSB) KASME data derived in MME and UE

Encryption key for 256(128 Encryption key for protection of user


KUPenc user plane (DRB) LSB) KeNB plane data derived in eNB and UE

Integrity key for 256(128 Integrity key for protection of RRC data
KRRCint RRC signalling(SRB) LSB) KeNB derived in eNB and UE

Encryption key for 256(128 Encryption key for protection of RRC


KRRCenc RRC LSB) KeNB data derived in eNB and UE

All LTE security keys (EPS) are 256 bits in length. The ciphering and integrity
keys for AS and NAS algorithms use only the 128 LSB(Least Significant Bits)
of the derived keys. For more detailed information on key derivation and key
hierarchy refer 3GPP 33.401 document. For KDF(Key Derivation Function)
specification refer 3GPP 33.220 document.

LTE Security termination points


Following table-2 summarizes LTE security termination points.

Termination Ciphering Integrity Protection

Required and terminated in Required and terminated in


NAS Signalling MME entity MME entity

Required and terminated in


U-plane data eNB entity Not needed
RRC Required and terminated in Required and terminated in
Signalling(AS) eNB entity eNB entity

MAC
Signalling(AS) Not needed Not needed

You might also like