5G Authentication Device Master Key Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G communication systems, the generation of a common master key using EAP-AKA protocol often fails due to the use of pseudo random functions not supported by user equipment (UE) and core network devices, leading to authentication failures.

Innovation Solution

An authentication device and method that acquire UE key derivation function (KDF) capabilities to select and generate a master key using a pseudo random function supported by the UE, ensuring compatibility and successful key exchange between UE and core network devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a core network device uses a pseudo random function not supported by a UE when generating a master key, then the core network device can use any available pseudo random function, but the UE and the core network device generate different master keys respectively, leading to authentication failure

Engineering Contradiction:
Improvecompatibility of pseudo random functionVSAvoidauthentication success rate
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by obtaining UE KDF capabilities information before generating the master key. The authentication device queries the UE's supported pseudo random functions in advance, selects a compatible function based on this information, and then generates the master key using the selected function. This preliminary capability assessment prevents authentication failure by ensuring both parties use the same pseudo random function.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the authentication device selects a pseudo random function based on UE KDF capabilities, then the master key generation becomes compatible with the UE, but the authentication device needs to acquire and process additional capability information

Engineering Contradiction:
Improveauthentication success rateVSAvoidcapability acquisition and processing
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies self-service by having the UE provide its own KDF capabilities information automatically during the registration process. The UE includes this capability information in its registration request message, eliminating the need for the authentication device to separately query or configure this information. The authentication device simply processes the provided capability information to select an appropriate pseudo random function.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11902776B2Authentication device, network device, communication system, authentication method, and non-transitory computer readable medium
Publication Date: 2024.02.13 NEC CORP
  • US11902776B2 patent drawing
  • US11902776B2 patent drawing
  • US11902776B2 patent drawing

AI summary

Provided is an authentication device capable of generating a master key suited to a UE in a 5GS. The authentication device (10) includes a communication unit (11) configured to, in registration processing of user equipment (UE), acquire UE key derivation function (KDF) capabilities indicating a pseudo random function supported by the UE, a selection unit (12) configured to select a pseudo random function used for generation of a master key related to the UE by use of the UE KDF capabilities, and a key generation unit (13) configured to generate a master key related to the UE by use of the selected pseudo random function.