Security key management system and method based on 5G communication module

By generating and securely isolating the master key in the 5G communication module, dynamically managing the subkeys, and combining physical isolation and computational randomization techniques, the problems of limited computing resources and vulnerability to attacks in existing 5G communication modules are solved, achieving efficient and secure key management and improving system performance and reliability.

CN121815256APending Publication Date: 2026-04-07JIANGSU FULIAN COMM TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-08
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Existing hierarchical key management schemes for 5G communication modules face challenges in practical applications, including limited computing and storage resources, signaling delays and service interruptions caused by high-frequency cell handover, vulnerability to power consumption, timing, or electromagnetic side-channel attacks, and a lack of real-time monitoring and alarms for key lifecycle and security events, making it difficult to balance performance and security.

Method used

By generating a master key and storing it securely in isolation, dynamically managing multi-level subkeys, generating them on demand and expiring them in seconds, and combining physical isolation, computational randomization, and shielding technologies to resist attacks, it provides real-time monitoring of security events, dual-mirror rollback capabilities, and visual alerts.

Benefits of technology

Significantly reduces module computation and energy consumption, enables seamless cell handover, improves performance and anti-attack capabilities, ensures key lifecycle controllability, and provides real-time security monitoring and alarms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121815256A_ABST
    Figure CN121815256A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of 5G communication modules, in particular to a security key management system and method based on a 5G communication module, a master key is generated after the 5G communication module and a network side complete mutual authentication, and the master key is safely isolated and stored as a trust basis of the whole system; according to service requirements, dynamically generating and managing multi-level sub-keys, and providing independent encryption and integrity protection for different functional domains; a sub-key is generated only when a real use scene is triggered, and a short-term caching and automatic expiration strategy is adopted, so that the security and the performance are both considered; performing encryption and integrity verification on all signaling and data streams by using the corresponding sub-keys; in a network switching or cell switching scene, pre-generating and quickly switching to a new key; according to the method, module operation and energy consumption overhead are greatly reduced through on-demand derivation and second-level expired caching strategies, non-inductive cell switching is achieved through a switching forecast pre-derivation and double-buffering atom switching mechanism, and time delay is remarkably shortened.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of 5G communication module technology, specifically to a secure key management system and method based on a 5G communication module. Background Technology

[0002] With the rapid commercialization of 5G networks, 5G communication modules have become a key component for terminal devices to access mobile networks;

[0003] 3GPP introduced a hierarchical key management mechanism in the 5G security architecture: After the terminal (UE) and the core network complete bidirectional AKA (Authentication and Key Agreement) authentication, they jointly generate a root key KAUSF; then, based on different functional domains (such as access and mobility management, NAS signaling, RRC control, user plane, non-3GPP interoperability, etc.), multiple sub-keys are "derived" level by level to encrypt and protect the integrity of signaling and data streams. In theory, this architecture can effectively isolate different security domains and avoid directly transmitting keys over the air interface, greatly enhancing network security.

[0004] However, existing hierarchical key management schemes for 5G communication modules face multiple challenges in practical applications: the security chip's one-time derivation of all subkeys leads to a shortage of computing and storage resources; frequent re-derivation in high-frequency cell handover scenarios causes signaling delays and service interruptions; the module is vulnerable to power consumption, timing, or electromagnetic side-channel attacks, yet lacks hardware isolation and randomization protection; at the same time, the lack of real-time monitoring and alarms for key lifecycles and security events makes fault location and security auditing difficult, making it hard to balance performance, reliability, and security. Therefore, this paper proposes a secure key management system and method based on 5G communication modules to address the above problems. Summary of the Invention

[0005] The purpose of this invention is to provide a secure key management system and method based on 5G communication modules, in order to solve the multiple challenges faced by existing hierarchical key management schemes for 5G communication modules in practical applications: the security chip generates all subkeys at once, leading to a shortage of computing and storage resources; frequent re-derivation in high-frequency cell handover scenarios causes signaling delays and service interruptions; the module is susceptible to power consumption, timing, or electromagnetic side-channel attacks, yet lacks hardware isolation and randomization protection; at the same time, the lack of real-time monitoring and alarms for key lifecycle and security events makes fault location and security auditing difficult, making it difficult to balance performance, reliability, and security.

[0006] To achieve the above objectives, the present invention provides the following technical solution:

[0007] A secure key management system and method based on a 5G communication module includes the following steps:

[0008] After the 5G communication module and the network side complete mutual authentication, a master key is generated and securely isolated for storage, serving as the trust foundation for the entire system. Multi-level sub-keys are dynamically generated and managed according to business needs, providing independent encryption and integrity protection for different functional domains. Sub-keys are derived only when triggered by real-world usage scenarios, employing short-term caching and automatic expiration strategies to balance security and performance. All signaling and data streams are encrypted and their integrity verified using the corresponding sub-keys. In network or cell handover scenarios, new keys are pre-generated and quickly switched to. Master and sub-keys are automatically destroyed and periodically refreshed. The frequency and scope of re-authentication are flexibly adjusted based on network performance, service type, and security posture. Dual mirroring or partition rollback capabilities are provided, and the integrity and origin of update packets are verified in the trusted link.

[0009] As a further optimization of the present invention, it also includes the following steps:

[0010] By combining physical isolation, computational randomization, and shielding technologies, it resists side-channel and physical attacks; it records critical security events in a trusted environment and tracks system status in real time through a visual interface and alarm mechanism, providing decision-making basis for operation and maintenance and security analysis.

[0011] As a further optimization of the present invention, in the process of encrypting and verifying the integrity of all signaling and data streams using the corresponding subkey, the non-access stratum signaling is encrypted by using the non-access stratum encryption key to encrypt the original non-access stratum message and by using the non-access stratum integrity key to calculate the message integrity code.

[0012] Radio resource control signaling encrypts the original radio resource control message using the target cell radio resource control encryption key and calculates the message integrity code using the target cell radio resource control integrity key;

[0013] User plane data is encrypted using the user plane encryption key, and a data integrity code is calculated using the user plane integrity key.

[0014] As a further optimization of this invention, the process of pre-generating and quickly switching to the new key is as follows:

[0015] Before issuing the radio resource control handover command, the base station sends the target cell identifier and related parameters to the 5G communication module side through a "handover notice" message;

[0016] After receiving the "handover notice", the 5G communication module calls the key derivation function in the background, and uses the original security anchor function key and the target cell identifier as input to pre-derive the target cell's target base station key, target cell radio resource control encryption key, and target cell radio resource control integrity key.

[0017] The 5G communication module maintains two sets of cache pointers in memory: the old key area and the new key area. When switching, only the pointers need to be switched atomically, without the need for re-deriving.

[0018] During the handover completion feedback phase, the 5G communication module uses the new target cell radio resource control encryption key and the target cell radio resource control integrity key to encrypt and send a simplified confirmation message. After the base station verifies the message, it immediately enables the new key and simultaneously marks the old key area as expired and clears it.

[0019] As a further optimization of the present invention, the key derivation function is a key derivation algorithm based on HMAC-SHA256.

[0020] As a further optimization of the present invention, the double-buffered switching pointer includes an active pointer, a spare pointer, and an old pointer, and the switching is completed through atomic operations.

[0021] As a further optimization of the present invention, the simplified confirmation message sent by the 5G communication module side using the new target cell radio resource control encryption key and the target cell radio resource control integrity key includes a 5G communication module side identifier, a handover confirmation flag and a timestamp, and is sent to the next-generation base station by the 5G communication module side using the new key through symmetric encryption and message authentication code protection.

[0022] As a further optimization of the present invention, it includes an authentication unit, which is used to generate a home network root key after the 5G communication module and the network side complete mutual authentication, and to securely isolate and store the root key.

[0023] The key derivation unit is used to dynamically generate multi-level sub-keys from the root key according to hierarchical labels based on business domain requirements;

[0024] The cache management unit is used to derive subkeys on demand when the corresponding function is called for the first time, and to intelligently cache them in the running memory, with second-level expiration and automatic destruction;

[0025] The encryption protection unit is used to call the corresponding subkey to encrypt and verify the integrity of non-access stratum signaling, radio resource control signaling and user plane data respectively.

[0026] The handover unit is used to pre-generate the subkey required for the new cell after receiving the "handover notice" in the cell handover scenario, and realize the instantaneous switching of the old and new keys through double-buffered pointers and simplified confirmation process;

[0027] The lifecycle management unit is used to automatically destroy or refresh all root keys and subkeys when the SIM card is removed, the device is restarted, or periodic re-authentication occurs;

[0028] The re-authentication policy unit is used to dynamically adjust the frequency of full or partial re-authentication based on network performance, service type, and security posture.

[0029] The firmware update unit provides dual-image and partition rollback capabilities, and verifies the integrity and origin of update packages in a trusted link.

[0030] As a further optimization of the present invention, it also includes a side-channel protection unit, which is used to resist power consumption, timing and electromagnetic side-channel attacks through physical isolation, computational randomization and shielding technology;

[0031] The operation and maintenance monitoring unit is used to record security event logs in a trusted execution environment and to monitor and analyze the status of the entire system in real time through a visual interface and alarm mechanism.

[0032] As a further optimization of the present invention, a computer program is stored thereon, and when the computer program is executed by a processor, it performs the steps of the method as described in any one of claims 1-7.

[0033] Compared with the prior art, the beneficial effects of the present invention are:

[0034] In this invention, the computational and energy consumption overhead of the module is significantly reduced by on-demand derivation and second-level expiration caching strategies. Seamless cell handover is achieved and latency is significantly shortened by utilizing "handover prediction" pre-derivation and double-buffered atomic handover mechanisms. Combined with multiple side-channel protection measures such as random delay, masking operation, and physical shielding, it effectively resists power consumption, timing, and electromagnetic attacks. Furthermore, security logs are recorded in a trusted execution environment, and with the assistance of visual alarms and multiple access security service interfaces, the entire lifecycle of the key is controllable and security events are monitored in real time, comprehensively improving the performance, reliability, and anti-attack capabilities of the 5G communication module. Attached Figure Description

[0035] Figure 1 This is a system block diagram of the security key management system based on a 5G communication module according to the present invention.

[0036] Figure 2 This is a flowchart of the security key management method based on a 5G communication module according to the present invention. Detailed Implementation

[0037] Please see Figure 1 and Figure 2 The present invention provides a technical solution:

[0038] A secure key management system and method based on a 5G communication module: After the 5G communication module UE detects the insertion of the Universal User Identity Module (USIM), it exchanges a random number RAND and an authentication token AUTN with the network side using the shared key K. It then generates the Home Network Authentication Server root key KAUSF based on HMAC-SHA256KDF and securely stores KAUSF in an isolated area within the Trusted Platform Module (TPM) or Secure Element (SE). When the 5G communication module uses the corresponding function for the first time, it uses the cryptographic derivation function KDF to establish the Secure Anchor Function Entity (SEAF), Access and Mobility Management Function Entity (AMF), Non-Access Stratum (NASenc) signaling encryption key, Non-Access Stratum (NASint) signaling integrity protection key, and non-3GPP interoperability key. The system uses tags and contexts such as entity N3IWF, next-generation base station node gNB, user plane encryption key UPenc, user plane integrity protection key UPint, radio resource control plane encryption key RRCenc, and radio resource control plane integrity protection key RRCint to derive security anchor key KSEAF, access and mobility management key KAMF, non-access stratum NAS signaling encryption key KNASenc, NAS signaling integrity key KNASint, non-3GPP interoperability key KN3IWF, base station layer key KgNB, and corresponding user plane encryption keys KUPenc, KUPint, and control plane encryption keys KRRCenc, KRRCint from KAUSF.

[0039] The frequently used NAS, wireless resource control (RRC), and user plane keys are intelligently cached in the running memory, and a second-level expiration time is set, after which they are automatically destroyed.

[0040] NAS signaling uses KNASenc and KNASint for encryption and integrity verification, RRC control signaling uses KRRCenc and KRRCint for protection, and user plane data uses KUPenc and KUPint for encryption.

[0041] Before handover in the same gNB cell, after receiving the "handover notice", the target cell KgNB and KRRC keys are pre-derived. By using double-buffered handover pointers and simplified ACK message procedures, the new and old keys are switched instantaneously.

[0042] When the SIM card is removed, the device is powered off and restarted, or re-authentication is triggered, the secure element automatically clears the KAUSF and all derived keys.

[0043] The system dynamically determines whether to perform a full or probe-based partial AKA refresh based on network quality indicators, service type, and geographical location, and supports remote distribution of re-authentication parameters by operators.

[0044] The device adopts a primary / backup firmware image area structure, and switches after digital signature verification. If the verification fails, it will automatically roll back.

[0045] Random delay and masking are introduced into the key operation, and metal shielding and differential traces are added in the module package to periodically check for anomalies and lock the key.

[0046] Record event summaries such as key generation, derivation, and erasure within the Trusted Execution Environment (TEE), provide a Multi-Access Security Service (MASS) interface, and enable real-time visual monitoring and alarms in the network management system.

[0047] In the process of encrypting and verifying the integrity of all signaling and data streams using the corresponding subkey:

[0048] NAS signaling through the original message M NAS Encrypted output using KNASenc And use KNASint to calculate message integrity code ;

[0049] Specifically:

[0050] ;

[0051] RRC control signaling transmits the original message M through... RRC Encrypted output using KRRCenc And use KRRCint to calculate the message integrity code. ;

[0052] Specifically:

[0053] ;

[0054] User plane data is obtained by processing the raw data D UP Encrypted output using KUPenc And use KUPint to calculate the data integrity code. ;

[0055] Specifically:

[0056] .

[0057] The process for pre-generating and quickly switching to the new key is as follows:

[0058] Before issuing the radio resource control handover command, the base station sends the target cell identifier and related parameters to the 5G communication module side through a "handover notice" message;

[0059] After receiving the "handover notice", the 5G communication module calls the key derivation function in the background, and uses the original security anchor function key and the target cell identifier as input to pre-derive the target cell's target base station key, target cell radio resource control encryption key, and target cell radio resource control integrity key.

[0060] The 5G communication module maintains two sets of cache pointers in memory: the old key area and the new key area. When switching, only the pointers need to be switched atomically, without the need for re-deriving.

[0061] During the handover completion feedback phase, the 5G communication module uses the new target cell radio resource control encryption key and the target cell radio resource control integrity key to encrypt and send a simplified confirmation message. After the base station verifies the message, it immediately activates the new key and simultaneously marks the old key area as expired and clears it, ensuring that the confidentiality and integrity of various services do not interfere with each other and improving the system's security isolation.

[0062] The key derivation function is based on the HMAC-SHA256 key derivation algorithm, which balances security strength and computational efficiency, and ensures the anti-collision and anti-forgery capabilities of the key derivation process.

[0063] The double-buffered switching pointer includes an active pointer, a backup pointer, and an old pointer, and the switching is completed through atomic operations. The double-buffered pointer and atomic switching avoid concurrent conflicts and resource contention, making the key switching process simple and efficient, and further reducing the risk of switching failure.

[0064] The simplified confirmation message sent by the 5G communication module side using the new target cell radio resource control encryption key and the target cell radio resource control integrity key includes the 5G communication module side identifier, handover confirmation flag and timestamp. It is sent to the next-generation base station by the 5G communication module side with the new key through symmetric encryption and message authentication code protection. The ACK content is simplified and protected by the new key, which can quickly complete the handover confirmation, while avoiding the leakage of redundant information, effectively improving security and signaling efficiency.

[0065] It includes an authentication unit, which generates a home network root key after the 5G communication module and the network side complete mutual authentication, and stores the root key securely and in isolation;

[0066] The key derivation unit is used to dynamically generate multi-level sub-keys from the root key according to hierarchical labels based on business domain requirements;

[0067] The cache management unit is used to derive subkeys on demand when the corresponding function is called for the first time, and to intelligently cache them in the running memory, with second-level expiration and automatic destruction;

[0068] The encryption protection unit is used to call the corresponding subkey to encrypt and verify the integrity of non-access stratum signaling, radio resource control signaling and user plane data respectively.

[0069] The handover unit is used to pre-generate the subkey required for the new cell after receiving the "handover notice" in the cell handover scenario, and realize the instantaneous switching of the old and new keys through double-buffered pointers and simplified confirmation process;

[0070] The lifecycle management unit is used to automatically destroy or refresh all root keys and subkeys when the SIM card is removed, the device is restarted, or periodic re-authentication occurs;

[0071] The re-authentication policy unit is used to dynamically adjust the frequency of full or partial re-authentication based on network performance, service type, and security posture.

[0072] The firmware update unit provides dual-image and partition rollback capabilities, and verifies the integrity and source of update packages in a trusted link. It divides and conquers key functional units, supports flexible deployment and expansion, facilitates rapid integration and operation and maintenance, and improves product adaptability.

[0073] It also includes a side-channel protection unit, which is used to resist power consumption, timing and electromagnetic side-channel attacks through physical isolation, computational randomization and shielding techniques;

[0074] The operation and maintenance monitoring unit is used to record security event logs in the trusted execution environment and to monitor and analyze the status of the entire system in real time through a visual interface and alarm mechanism. The combination of side-channel protection and real-time monitoring not only strengthens the defense against physical layer attacks, but also provides timely alarms for security events, realizing full-link security visualization.

[0075] It stores a computer program, which, when executed by a processor, runs the steps of any one of the methods described in claims 1-7, implements key management functions in a software programmable manner, supports remote upgrades and flexible customization, and facilitates subsequent function iterations and security patch releases.

[0076] This article uses specific examples to illustrate the principles and implementation methods of the present invention. The above examples are only for the purpose of helping to understand the method and core ideas of the present invention. The above descriptions are only preferred embodiments of the present invention. It should be noted that due to the limitations of textual expression, while there are objectively infinite specific structures, those skilled in the art can make several improvements, modifications, or changes without departing from the principles of the present invention, and can also combine the above technical features in an appropriate manner. These improvements, modifications, changes, or combinations, or the direct application of the inventive concept and technical solution to other situations without modification, should all be considered within the scope of protection of the present invention.

Claims

1. A secure key management method based on a 5G communication module, characterized in that, Includes the following steps: After the 5G communication module and the network side complete mutual authentication, a master key is generated and stored securely and isolated as the trust basis for the entire system. Dynamically generate and manage multi-level sub-keys according to business needs, and provide independent encryption and integrity protection for different functional domains; Subkeys are derived only when triggered in real-world use cases, and a short-term caching and automatic expiration strategy is adopted to balance security and performance. All signaling and data streams are encrypted and their integrity verified using the corresponding subkeys; In network or cell handover scenarios, pre-generate and quickly switch to the new key; Automatic destruction and periodic refresh of master and sub-keys; The frequency and scope of re-authentication should be flexibly adjusted based on network performance, service type, and security posture. Provides dual-image or partition rollback capabilities, and verifies the integrity and origin of update packages in a trusted link.

2. The secure key management method based on a 5G communication module according to claim 1, characterized in that: It also includes the following steps: Combining physical isolation, computational randomization, and shielding techniques to resist side-channel and physical attacks; Record critical security events in a trusted environment and track system status in real time through a visual interface and alarm mechanism to provide decision-making basis for operation and maintenance and security analysis.

3. The secure key management method based on a 5G communication module according to claim 1, characterized in that: In the process of encrypting and verifying the integrity of all signaling and data streams using the corresponding subkey, the non-access stratum signaling is encrypted by using the non-access stratum encryption key to encrypt the original non-access stratum message and by using the non-access stratum integrity key to calculate the message integrity code. Radio resource control signaling encrypts the original radio resource control message using the target cell radio resource control encryption key and calculates the message integrity code using the target cell radio resource control integrity key; User plane data is encrypted using the user plane encryption key, and a data integrity code is calculated using the user plane integrity key.

4. The secure key management method based on a 5G communication module according to claim 1, characterized in that: The process of pre-generating and quickly switching to the new key is as follows: Before issuing the radio resource control handover command, the base station sends the target cell identifier and related parameters to the 5G communication module side through a "handover notice" message; After receiving the "handover notice", the 5G communication module calls the key derivation function in the background, and uses the original security anchor function key and the target cell identifier as input to pre-derive the target cell's target base station key, target cell radio resource control encryption key, and target cell radio resource control integrity key. The 5G communication module maintains two sets of cache pointers in memory: the old key area and the new key area. When switching, only the pointers need to be switched atomically, without the need for re-deriving. During the handover completion feedback phase, the 5G communication module uses the new target cell radio resource control encryption key and the target cell radio resource control integrity key to encrypt and send a simplified confirmation message. After the base station verifies the message, it immediately enables the new key and simultaneously marks the old key area as expired and clears it.

5. The secure key management method based on a 5G communication module according to claim 4, characterized in that: The key derivation function is a key derivation algorithm based on HMAC-SHA256.

6. The secure key management method based on a 5G communication module according to claim 4, characterized in that: The double-buffered switching pointer includes an active pointer, a spare pointer, and an old pointer, and the switching is completed through atomic operations.

7. The secure key management method based on a 5G communication module according to claim 4, characterized in that: The simplified confirmation message sent by the 5G communication module side using the new target cell radio resource control encryption key and the target cell radio resource control integrity key includes the 5G communication module side identifier, handover confirmation flag and timestamp, and is sent to the next-generation base station by the 5G communication module side using the new key through symmetric encryption and message authentication code protection.

8. A security key management system based on a 5G communication module according to any one of claims 1-7, characterized in that: It includes an authentication unit, which generates a home network root key after the 5G communication module and the network side complete mutual authentication, and stores the root key securely and in isolation; The key derivation unit is used to dynamically generate multi-level sub-keys from the root key according to hierarchical labels based on business domain requirements; The cache management unit is used to derive subkeys on demand when the corresponding function is called for the first time, and to intelligently cache them in the running memory, with second-level expiration and automatic destruction; The encryption protection unit is used to call the corresponding subkey to encrypt and verify the integrity of non-access stratum signaling, radio resource control signaling and user plane data respectively. The handover unit is used to pre-generate the subkey required for the new cell after receiving the "handover notice" in the cell handover scenario, and realize the instantaneous switching of the old and new keys through double-buffered pointers and simplified confirmation process; The lifecycle management unit is used to automatically destroy or refresh all root keys and subkeys when the SIM card is removed, the device is restarted, or periodic re-authentication occurs; The re-authentication policy unit is used to dynamically adjust the frequency of full or partial re-authentication based on network performance, service type, and security posture. The firmware update unit provides dual-image and partition rollback capabilities, and verifies the integrity and origin of update packages in a trusted link.

9. The security key management system based on a 5G communication module according to claim 8, characterized in that: It also includes a side-channel protection unit, which is used to resist power consumption, timing and electromagnetic side-channel attacks through physical isolation, computational randomization and shielding techniques; The operation and maintenance monitoring unit is used to record security event logs in a trusted execution environment and to monitor and analyze the status of the entire system in real time through a visual interface and alarm mechanism.

10. The security key management system based on a 5G communication module according to claim 1, wherein a computer program is stored thereon, characterized in that... When the computer program is executed by a processor, it performs the steps of the method as described in any one of claims 1-7.