Cellular Network Message Security via Key Derivation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security solutions for cellular networks, particularly in 5G and LTE, face issues with protecting discovery messages and Direct Communication Request (DCR) messages over the PC5 interface, including vulnerability to attacks, lack of interoperability, and high complexity, as well as inadequate protection for long messages.
Innovation Solution
A method is proposed that enhances security by using a key derivation function to generate a keystream for encrypting messages, incorporating a freshness value and confidentiality key, with optional Message Integrity Check, and selecting the appropriate encryption key based on configured DUCK or DUSK, to ensure secure communication and minimal interaction with the Core Network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing security solutions in TS 33.303 are used to protect discovery messages, then some level of security is provided, but the solutions are vulnerable to attacks and do not ensure integrity of nodes
Solution Approach 1:
The patent changes the cryptographic parameters by introducing a new key derivation function that incorporates freshness values and uses different key management approaches (DUCK/DUSK selection) to enhance security protection against attacks while maintaining compatibility with existing systems
Solution Approach 2:
The patent replaces the existing security mechanism with an improved cryptographic approach using key derivation functions and keystream generation, substituting the vulnerable mechanical security system with a more robust cryptographic system that ensures message integrity and node security
2Reliability
If existing security solutions are applied to protect Direct Communication Request messages, then security is provided, but interoperability is lacking and complexity is too high
Solution Approach 1:
The patent creates a universal security solution that works across different scenarios (discovery messages and DCR messages) using a unified key derivation approach, reducing complexity while maintaining security and improving interoperability through a standardized method
Solution Approach 2:
The patent simplifies the security mechanism by changing parameters such as using a unified keystream generation approach and standardized key selection (DUCK/DUSK), reducing implementation complexity while maintaining security protection
3Reliability
If existing security solutions are used, then short messages can be protected, but long discovery messages longer than 32 bytes cannot be protected
Solution Approach 1:
The patent applies segmentation by dividing long messages into multiple segments and applying the security mechanism to each segment independently using the key derivation function and keystream, enabling protection of messages of any length while maintaining security integrity
Solution Approach 2:
The patent introduces dynamic key derivation that adapts to message length by incorporating freshness values and using configurable parameters, allowing the security mechanism to dynamically adjust to protect both short and long messages effectively
Data Source
AI summary
The invention relates to a method for operating a communication system including a. a first station preparing a message including a relay service code indicative of the type of service a user needs for relaying combined with a communication key or an indication of a communication key to be used for communication with a relay station: b. the first station generating a keystream by applying a key derivation function on at least a confidentiality key and freshness value, c. the first station ciphering the message with the key stream.


