Algorithm-Specific Cryptographic Key Segmentation in Mobile Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile communication systems like GSM and UMTS face security vulnerabilities due to the use of the A5/2 cryptographic algorithm, which can be broken, leading to interception and decryption of traffic, and the same cryptographic key being used across different algorithms, making them susceptible to attacks.
Innovation Solution
Implementing an algorithm-specific modification of the security key generated during the key agreement procedure in mobile communication systems, where the basic security key is modified based on information representative of the selected algorithm to enhance security, allowing for the use of enhanced cryptographic security algorithms while maintaining support for basic algorithms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If the same cryptographic key is used across different security algorithms, then key management is simplified, but security is compromised when one algorithm is broken
Solution Approach 1:
The patent segments the single cryptographic key into multiple algorithm-specific keys (Kc1, Kc2, Kc3, etc.), where each key is dedicated to a specific security algorithm (A5/1, A5/2, A5/3, etc.). This segmentation ensures that breaking one algorithm does not compromise the security of other algorithms, as each has its own independent key.
Solution Approach 2:
The patent applies local quality by making each cryptographic key unique to its specific algorithm context. Instead of a uniform key across all algorithms, each algorithm receives a locally optimized key (Kc_i) that is specifically tailored to its security requirements and characteristics.
2Reliability
If algorithm-specific key modification is implemented, then security against broken algorithms is improved, but system complexity increases
Solution Approach 1:
The patent implements preliminary action by pre-defining the relationship between algorithms and their corresponding keys during the key agreement procedure. The system proactively establishes algorithm-specific keys (Kc1, Kc2, Kc3) before any security operations occur, based on the selected algorithm, rather than attempting to manage key complexity during runtime.
Solution Approach 2:
The patent changes the key parameter from a single universal key to multiple algorithm-specific keys. This parameter change is achieved by modifying the key derivation process to incorporate algorithm identification, transforming the key generation function to output different keys based on the selected algorithm index.
3Ease of manufacture
If existing hardware-implemented algorithms are kept unchanged, then implementation cost is reduced, but security enhancement is limited
Solution Approach 1:
The patent introduces an intermediary layer (the key modification function) between the existing hardware algorithms and the security key. This intermediary transforms the basic security key into algorithm-specific keys without modifying the hardware algorithms themselves, thus preserving implementation ease while enhancing security through software-based key management.
Data Source
AI summary
A basic idea according to the invention is to enhance or update the basic cryptographic security algorithms by an algorithm-specific modification of the security key information generated in the normal key agreement procedure of the mobile communication system. For communication with the mobile terminal, the network side normally selects an enhanced version of one of the basic cryptographic security algorithms supported by the mobile, and transmits information representative of the selected algorithm to the mobile terminal. The basic security key resulting from the key agreement procedure (AKA, 10) between the mobile terminal and the network is then modified (22) in dependence on the selected algorithm to generate an algorithm-specific security key. The basic security algorithm (24) is then applied with this algorithm-specific security key as key input to enhance security for protected communication in the mobile communications network.


