Access-Specific Key Derivation for Mobile Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Internet protocols are not designed for mobile use, leading to disruptions in data transmission when mobile terminals change IP addresses, and there is a lack of suitable protocols for securing data transmission between mobile terminals and access networks, especially when the authentication server does not support mobility management.

Innovation Solution

A method and system for providing an access-specific key for securing data transmission between a mobile terminal and an access network, where an authentication server generates a session key, which is used to derive a base key sent to an interworking proxy server to create access network-specific keys, ensuring secure data transmission even when the authentication server does not support mobility management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional Internet protocols are used for mobile devices, then protocol compatibility and wide user base coverage are achieved, but data transmission is interrupted when IP address changes occur

Engineering Contradiction:
Improveprotocol compatibilityVSAvoiddata transmission continuity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the key management function by introducing a key derivation function that operates independently from the authentication server. This allows the mobile device to locally derive session keys from a master key, ensuring continuous secure communication even when moving between networks and IP addresses change, thus resolving the contradiction between protocol compatibility and transmission continuity.

Inventive Principle:
Principle #1Segmentation

2Reliability

If the authentication server implements mobility management functions, then seamless handover between networks is achieved, but device complexity and protocol requirements increase

Engineering Contradiction:
Improvemobility management capabilityVSAvoidauthentication server complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the key derivation functionality from the authentication server and implements it locally in the mobile device through a key derivation function. This extraction reduces the complexity requirements for the authentication server while maintaining seamless mobility management capabilities, as the device can independently handle key generation for handover scenarios.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The mobile device performs self-service by locally deriving session keys from the master key using the key derivation function. This eliminates the need for the authentication server to directly manage mobility-specific key operations, reducing server complexity while enabling reliable mobility management through the device's autonomous key management capability.

Inventive Principle:
Principle #25Self-service

3Reliability

If access-specific keys are derived for each data transmission path, then security is improved, but key management complexity increases

Engineering Contradiction:
Improvedata transmission securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by establishing a master key relationship between the mobile device and the authentication server before actual data transmission begins. This pre-established trust relationship enables the device to autonomously derive access-specific keys for different transmission paths without requiring complex centralized key management, thus improving security while keeping key management relatively simple.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2052517B1Method and system for providing an access specific key
Publication Date: 2016.11.02 SIEMENS AG
  • EP2052517B1 patent drawingFigure 1~2
  • EP2052517B1 patent drawingFigure 3
  • EP2052517B1 patent drawingFigure 4

AI summary

Method for providing an access specific key for securing of a data transfer between a mobile terminal (1) and a node of an access net (2), wherein with an authentication of the mobile terminal (1), a authentication server (4A) generates a session key, from which a basic key is derived and transferred to a interworking-proxy-server (7). The interworking-proxy-server derives the access specific key from the transferred basis key and provides said key to the node of the access net (2).