5G Anchor Key Generation for Multi-Access Key Separation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge in 5G networks is generating a unified anchor key that supports compatibility across various access modes, including 3GPP, trusted non-3GPP, and untrusted non-3GPP access, which existing methods have not adequately addressed.
Innovation Solution
A method for anchor key generation that involves a communications device receiving an indication identifier to determine the access mode, generating an intermediate key based on this identifier, and then deriving a lower-layer key using a key generation algorithm, such as KDF or PRF, to create a unified anchor key that separates keys for different access modes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a unified anchor key is generated to support multiple access modes, then compatibility across 3GPP, trusted non-3GPP, and untrusted non-3GPP access modes is improved, but key management complexity increases
Solution Approach 1:
The patent segments the key management system into distinct components: anchor keys specific to each access mode (3GPP, trusted non-3GPP, untrusted non-3GPP), and lower-layer keys derived from these anchor keys. This segmentation allows each access mode to have its own dedicated anchor key while maintaining a systematic derivation process for lower-layer keys, thereby achieving multi-mode compatibility without overwhelming key management complexity.
Solution Approach 2:
The patent introduces a hierarchical dimension to key management by establishing multiple levels: anchor keys at the top level (specific to access modes) and lower-layer keys at the derivation level. This dimensional structure allows the system to manage keys for different access modes independently at the anchor key level while maintaining unified control through the derivation relationship, resolving the contradiction between versatility and complexity.
2Reliability
If separate keys are generated for different access modes, then security is improved, but key negotiation complexity increases
Solution Approach 1:
The patent applies preliminary action by pre-establishing access-mode-specific anchor keys before actual communication occurs. These anchor keys are generated and stored in advance for each access mode, so when key negotiation is needed, the system can directly derive lower-layer keys from the appropriate pre-existing anchor key without complex real-time decisions, thus maintaining high security while simplifying the negotiation process.
Solution Approach 2:
The patent uses anchor keys as intermediaries between the authentication process and the actual communication security. The anchor keys serve as a mediator that connects the access mode identification to the specific lower-layer key derivation, allowing the system to maintain separate security contexts for different access modes while using a unified derivation mechanism, thereby improving security without proportionally increasing negotiation complexity.
3Reliability
If key separation is implemented for different access modes, then key isolation security is improved, but system flexibility decreases
Solution Approach 1:
The patent implements universality through the key derivation function that can operate with any anchor key regardless of access mode. The same derivation mechanism and function are used universally across 3GPP, trusted non-3GPP, and untrusted non-3GPP access modes, allowing the system to maintain strong key isolation (different anchor keys for different modes) while preserving flexibility through a unified, adaptable derivation process that can handle any access mode scenario.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Embodiments of this application provide an anchor key generation method, device, and system. The method includes: receiving, by a first communications device, an indication identifier sent by a second communications device, where the indication identifier is used to indicate an access mode of a terminal; sending, by the first communications device, the indication identifier to a third communications device; receiving, by the first communications device, an intermediate key returned by the third communications device, where the intermediate key is generated based on the indication identifier; generating, by the first communications device, an anchor key based on the intermediate key, where the anchor key is corresponding to the access mode of the terminal; and sending, by the first communications device, the anchor key to the second communications device, so that the second communications device derives a lower-layer key for the access mode based on the anchor key. In the method, a unified anchor key can be generated for different access modes, and the anchor key of the different access modes is separated from a lower-layer key generated based on the anchor key.