Air Interface Key Management in HSPA+ Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The current 3GPP standard lacks a method for generating and distributing the intermediate keys KASMEU, CKU, and IKU in HSPA+ architecture, which compromises the security of Node B+ due to its unsafe condition and incomplete key hierarchy.

Innovation Solution

A method and system for managing air interface keys, where SGSN+ or MSC/VLR+ generates and transmits intermediate keys KASMEU, CKU, and IKU to RNC+, enabling RNC+ to deduce and distribute these keys to UE+, ensuring secure ciphering and integrity protection by updating key hierarchies and algorithms as needed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If RNC function is completely transferred to Node B+ in HSPA+ architecture, then network flattening and simplified architecture are achieved, but security of Node B+ deteriorates due to unsafe condition and incomplete key hierarchy

Engineering Contradiction:
Improvenetwork architecture complexityVSAvoidsecurity of Node B+
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the key hierarchy into multiple levels: root key K, intermediate key KASMEU, and derived keys CKU/IKU. This segmentation allows different key management functions to be distributed appropriately - KASMEU is generated and stored securely in SGSN+/MSC/VLR+ and UE+, while Node B+ only receives derived keys for specific ciphering operations, thus maintaining security while achieving architectural simplification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces KASMEU as an intermediary key between the root key K and the derived keys CKU/IKU. This intermediary key acts as a mediator that is generated by authenticated entities (SGSN+/MSC/VLR+ and UE+) but not stored in the unsafe Node B+, thereby providing security mediation while enabling the flattened architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If current HSPA+ key hierarchy is used without generation and distribution method, then architectural simplicity is maintained, but security functionality is incomplete and vulnerable

Engineering Contradiction:
Improvekey management complexityVSAvoidsecurity functionality
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements preliminary action by establishing the complete key generation and distribution methodology before deployment. The AKA authentication process pre-generates KASMEU, and the system pre-defines the key derivation relationships (KASMEU → CKU/IKU) so that when Node B+ needs to perform ciphering, the security framework is already in place and functional.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the key parameters from the traditional UMTS structure (K → CK/IK) to the HSPA+ structure (K → KASMEU → CKU/IKU). This parameter change in the key hierarchy enables enhanced security functionality while maintaining manageable complexity through systematic key derivation relationships.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8565433B2Method and system for managing air interface key
Publication Date: 2013.10.22 ZTE CORP
  • US8565433B2 patent drawing
  • US8565433B2 patent drawing
  • US8565433B2 patent drawing

AI summary

A method and system for managing an air interface key are provided in the present invention, which relate to the communication field; the method including: a serving GPRS Support Node+ (SGSN+) or a Mobile Switching Centre/Visitor Location Register+ (MSC/VLR+) transmits a key distributing message to a Radio Network Controller+ (RNC+), wherein the message carries at least one of an intermediate key KASMEU, a ciphering key CKU or an integrity key IKU.