Authentication Key Storage Segmentation for Network Handover

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In telecommunications networks, particularly in LTE environments, UE devices face challenges in managing authentication keys across multiple security contexts, leading to potential key collisions and authentication failures during handovers between different network technologies.

Innovation Solution

A method and system for managing security key architecture in UE devices, which involves generating and storing authentication keys in context-specific elementary files on a removable SIM or non-volatile memory, ensuring that keys from one security context do not overwrite those from another, by using adapter components to manage key storage and retrieval based on access technologies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If authentication keys are stored in a common location for multiple security contexts, then storage simplicity is improved, but key collisions and authentication failures occur during handovers

Engineering Contradiction:
Improvestorage simplicityVSAvoidauthentication success rate
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent divides the storage location into context-specific elementary files within the SIM card, where each security context (e.g., GERAN, UTRAN, E-UTRAN) has its own dedicated file. This segmentation prevents key collisions by ensuring that authentication keys from different security contexts are stored in separate, isolated locations, thereby maintaining authentication reliability during handovers between different network technologies.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If multiple authentication procedures are negotiated for different network technologies, then network compatibility is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork compatibilityVSAvoidauthentication management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication management mechanism that handles multiple security contexts through a common adapter layer. This adapter component provides multi-functional support for different network technologies (GERAN, UTRAN, E-UTRAN) by uniformly managing key storage and retrieval operations across context-specific files, thereby reducing the apparent complexity for the upper layers while maintaining broad network compatibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an adapter component as an intermediary between the authentication functions and the key storage mechanisms. This adapter manages the complexity of multiple authentication procedures by providing a unified interface that handles context-specific key retrieval automatically, allowing the system to support multiple network technologies without exposing the underlying complexity to the application layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If authentication keys are stored in removable SIM card, then security and flexibility are improved, but key management complexity across multiple contexts increases

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the SIM card storage into context-specific elementary files, where each file is dedicated to a particular security context (GERAN, UTRAN, E-UTRAN). This segmentation maintains security by isolating keys from different contexts while the adapter layer manages the complexity of accessing the appropriate file based on the current security context, thereby preventing key management errors without compromising security.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8645695B2System and method for managing security key architecture in multiple security contexts of a network environment
Publication Date: 2014.02.04 MALIKIE INNOVATIONS LTD
  • US8645695B2 patent drawing
  • US8645695B2 patent drawing
  • US8645695B2 patent drawing

AI summary

A user equipment (UE) device that is able to engage in multiple security contexts contains a key generator to generate one or more authentication keys for authentication of the UE device in a particular security context and a component configured to facilitate storing of the authentication keys in a subscriber identity module (SIM) if an elementary file (EF) structure for the particular security context is available in the SIM and to facilitate storing of the authentication keys in a nonvolatile memory (NVM) of the UE device if the EF structure is not found in the SIM.