Access-Specific Key Derivation for Mobile Data Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional Internet protocols are not designed for mobile use, leading to disruptions in data transmission when mobile terminals change IP addresses, and there is a lack of suitable protocols for securing data transmission between mobile terminals and access networks, especially when the authentication server does not support mobility management.
Innovation Solution
A method and system for providing an access-specific key for securing data transmission between a mobile terminal and an access network, where an authentication server generates a session key, which is used to derive a base key sent to an interworking proxy server to create access network-specific keys, ensuring secure data transmission even when the authentication server does not support mobility management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional Internet protocols are used for mobile devices, then protocol compatibility and wide user base coverage are achieved, but data transmission is interrupted when IP address changes occur
Solution Approach 1:
The patent segments the key management function by introducing a key derivation function that operates independently from the authentication server. This allows the mobile device to locally derive session keys from a master key, ensuring continuous secure communication even when moving between networks and IP addresses change, thus resolving the contradiction between protocol compatibility and transmission continuity.
2Reliability
If the authentication server implements mobility management functions, then seamless handover between networks is achieved, but device complexity and protocol requirements increase
Solution Approach 1:
The patent extracts the key derivation functionality from the authentication server and implements it locally in the mobile device through a key derivation function. This extraction reduces the complexity requirements for the authentication server while maintaining seamless mobility management capabilities, as the device can independently handle key generation for handover scenarios.
Solution Approach 2:
The mobile device performs self-service by locally deriving session keys from the master key using the key derivation function. This eliminates the need for the authentication server to directly manage mobility-specific key operations, reducing server complexity while enabling reliable mobility management through the device's autonomous key management capability.
3Reliability
If access-specific keys are derived for each data transmission path, then security is improved, but key management complexity increases
Solution Approach 1:
The patent applies preliminary action by establishing a master key relationship between the mobile device and the authentication server before actual data transmission begins. This pre-established trust relationship enables the device to autonomously derive access-specific keys for different transmission paths without requiring complex centralized key management, thus improving security while keeping key management relatively simple.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
Method for providing an access specific key for securing of a data transfer between a mobile terminal (1) and a node of an access net (2), wherein with an authentication of the mobile terminal (1), a authentication server (4A) generates a session key, from which a basic key is derived and transferred to a interworking-proxy-server (7). The interworking-proxy-server derives the access specific key from the transferred basis key and provides said key to the node of the access net (2).