Algorithm-Specific Cryptographic Key Segmentation in Mobile Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile communication systems like GSM and UMTS face security vulnerabilities due to the use of the A5/2 cryptographic algorithm, which can be broken, leading to interception and decryption of traffic, and the same cryptographic key being used across different algorithms, making them susceptible to attacks.

Innovation Solution

Implementing an algorithm-specific modification of the security key generated during the key agreement procedure in mobile communication systems, where the basic security key is modified based on information representative of the selected algorithm to enhance security, allowing for the use of enhanced cryptographic security algorithms while maintaining support for basic algorithms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If the same cryptographic key is used across different security algorithms, then key management is simplified, but security is compromised when one algorithm is broken

Engineering Contradiction:
Improvekey management complexityVSAvoidsecurity reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the single cryptographic key into multiple algorithm-specific keys (Kc1, Kc2, Kc3, etc.), where each key is dedicated to a specific security algorithm (A5/1, A5/2, A5/3, etc.). This segmentation ensures that breaking one algorithm does not compromise the security of other algorithms, as each has its own independent key.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by making each cryptographic key unique to its specific algorithm context. Instead of a uniform key across all algorithms, each algorithm receives a locally optimized key (Kc_i) that is specifically tailored to its security requirements and characteristics.

Inventive Principle:
Principle #3Local quality

2Reliability

If algorithm-specific key modification is implemented, then security against broken algorithms is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-defining the relationship between algorithms and their corresponding keys during the key agreement procedure. The system proactively establishes algorithm-specific keys (Kc1, Kc2, Kc3) before any security operations occur, based on the selected algorithm, rather than attempting to manage key complexity during runtime.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the key parameter from a single universal key to multiple algorithm-specific keys. This parameter change is achieved by modifying the key derivation process to incorporate algorithm identification, transforming the key generation function to output different keys based on the selected algorithm index.

Inventive Principle:
Principle #35Parameter changes

3Ease of manufacture

If existing hardware-implemented algorithms are kept unchanged, then implementation cost is reduced, but security enhancement is limited

Engineering Contradiction:
Improveimplementation easeVSAvoidsecurity level
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent introduces an intermediary layer (the key modification function) between the existing hardware algorithms and the security key. This intermediary transforms the basic security key into algorithm-specific keys without modifying the hardware algorithms themselves, thus preserving implementation ease while enhancing security through software-based key management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7660417B2Enhanced security design for cryptography in mobile communication systems
Publication Date: 2010.02.09 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US7660417B2 patent drawing
  • US7660417B2 patent drawing
  • US7660417B2 patent drawing

AI summary

A basic idea according to the invention is to enhance or update the basic cryptographic security algorithms by an algorithm-specific modification of the security key information generated in the normal key agreement procedure of the mobile communication system. For communication with the mobile terminal, the network side normally selects an enhanced version of one of the basic cryptographic security algorithms supported by the mobile, and transmits information representative of the selected algorithm to the mobile terminal. The basic security key resulting from the key agreement procedure (AKA, 10) between the mobile terminal and the network is then modified (22) in dependence on the selected algorithm to generate an algorithm-specific security key. The basic security algorithm (24) is then applied with this algorithm-specific security key as key input to enhance security for protected communication in the mobile communications network.