5G Security Mode Key Selection for Shared Operator Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods fail to provide differentiated integrity protection for different operators sharing a co-constructed and shared 5G base station, which may require varying service requirements such as ultra-low latency and independent user data integrity protection.

Innovation Solution

A configuration method and system that generates adaptive integrity protection and encryption keys based on operator-specific key generation algorithms, using integrity protection and encryption algorithms, and operator identification to ensure secure communication in a shared 5G base station.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a shared 5G base station is used by multiple operators, then resource utilization and cost efficiency are improved, but differentiated integrity protection for different operators cannot be provided

Engineering Contradiction:
Improveshared carrier supportVSAvoidintegrity protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the key generation process by operator identification. The network device determines different key generation algorithms for different operators based on their operator identification, allowing each operator to have independent security parameters while sharing the same physical base station infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by customizing security parameters locally for each operator. Different integrity protection algorithms and key generation methods are applied to different operators' data streams, ensuring that each operator receives tailored security protection appropriate to their specific requirements.

Inventive Principle:
Principle #3Local quality

2Reliability

If operator-specific key generation algorithms are used, then differentiated integrity protection is improved, but system complexity increases

Engineering Contradiction:
Improveintegrity protectionVSAvoidkey management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-configuring multiple key generation algorithms in the network device before operation. When a user establishes a connection, the appropriate algorithm is automatically selected based on operator identification, eliminating the need for real-time algorithm negotiation or complex runtime decision-making.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses operator identification as an intermediary to bridge the shared infrastructure and differentiated security requirements. This intermediary enables the system to automatically select appropriate key generation algorithms without requiring direct complex interactions between multiple security management systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12490096B2Configuration method, device and system of security mode and computer-readable storage medium
Publication Date: 2025.12.02 CHINA TELECOM CORP LTD
  • US12490096B2 patent drawing
  • US12490096B2 patent drawing
  • US12490096B2 patent drawing

AI summary

This disclosure discloses a configuration method, a configuration device, and a configuration system of security mode and a computer readable storage medium, relating to mobile communications technologies. The configuration method of security mode includes: acquiring an integrity protection algorithm, an encryption algorithm, an original key and an operator identification of a core network from the core network, wherein the original key is also sent to a user to start a security mode, the core network is a core network of a first operator or a second operator, and the first operator and the second operator use a same shared carrier in a co-construction and sharing base station; determining a key generation algorithm preset by an operator to which the user belongs according to the operator identification; generating an integrity protection key and an encryption key of the user according to the key generation algorithm and the original key; and sending a security mode command to a terminal of the user, wherein the security mode command comprises verification information encrypted by the integrity protection key of the user, the integrity protection algorithm and the encryption algorithm, and the terminal has the key generation algorithm preset by the operator to which the user belongs.