Air Interface Key Management in HSPA+ Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The current 3GPP standard lacks a method for generating and distributing the intermediate keys KASMEU, CKU, and IKU in HSPA+ architecture, which compromises the security of Node B+ due to its unsafe condition and incomplete key hierarchy.
Innovation Solution
A method and system for managing air interface keys, where SGSN+ or MSC/VLR+ generates and transmits intermediate keys KASMEU, CKU, and IKU to RNC+, enabling RNC+ to deduce and distribute these keys to UE+, ensuring secure ciphering and integrity protection by updating key hierarchies and algorithms as needed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If RNC function is completely transferred to Node B+ in HSPA+ architecture, then network flattening and simplified architecture are achieved, but security of Node B+ deteriorates due to unsafe condition and incomplete key hierarchy
Solution Approach 1:
The patent segments the key hierarchy into multiple levels: root key K, intermediate key KASMEU, and derived keys CKU/IKU. This segmentation allows different key management functions to be distributed appropriately - KASMEU is generated and stored securely in SGSN+/MSC/VLR+ and UE+, while Node B+ only receives derived keys for specific ciphering operations, thus maintaining security while achieving architectural simplification.
Solution Approach 2:
The patent introduces KASMEU as an intermediary key between the root key K and the derived keys CKU/IKU. This intermediary key acts as a mediator that is generated by authenticated entities (SGSN+/MSC/VLR+ and UE+) but not stored in the unsafe Node B+, thereby providing security mediation while enabling the flattened architecture.
2Device complexity
If current HSPA+ key hierarchy is used without generation and distribution method, then architectural simplicity is maintained, but security functionality is incomplete and vulnerable
Solution Approach 1:
The patent implements preliminary action by establishing the complete key generation and distribution methodology before deployment. The AKA authentication process pre-generates KASMEU, and the system pre-defines the key derivation relationships (KASMEU → CKU/IKU) so that when Node B+ needs to perform ciphering, the security framework is already in place and functional.
Solution Approach 2:
The patent changes the key parameters from the traditional UMTS structure (K → CK/IK) to the HSPA+ structure (K → KASMEU → CKU/IKU). This parameter change in the key hierarchy enables enhanced security functionality while maintaining manageable complexity through systematic key derivation relationships.
Data Source
AI summary
A method and system for managing an air interface key are provided in the present invention, which relate to the communication field; the method including: a serving GPRS Support Node+ (SGSN+) or a Mobile Switching Centre/Visitor Location Register+ (MSC/VLR+) transmits a key distributing message to a Radio Network Controller+ (RNC+), wherein the message carries at least one of an intermediate key KASMEU, a ciphering key CKU or an integrity key IKU.


