Cellular Network Message Security via Key Derivation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security solutions for cellular networks, particularly in 5G and LTE, face issues with protecting discovery messages and Direct Communication Request (DCR) messages over the PC5 interface, including vulnerability to attacks, lack of interoperability, and high complexity, as well as inadequate protection for long messages.

Innovation Solution

A method is proposed that enhances security by using a key derivation function to generate a keystream for encrypting messages, incorporating a freshness value and confidentiality key, with optional Message Integrity Check, and selecting the appropriate encryption key based on configured DUCK or DUSK, to ensure secure communication and minimal interaction with the Core Network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing security solutions in TS 33.303 are used to protect discovery messages, then some level of security is provided, but the solutions are vulnerable to attacks and do not ensure integrity of nodes

Engineering Contradiction:
Improvesecurity protectionVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the cryptographic parameters by introducing a new key derivation function that incorporates freshness values and uses different key management approaches (DUCK/DUSK selection) to enhance security protection against attacks while maintaining compatibility with existing systems

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces the existing security mechanism with an improved cryptographic approach using key derivation functions and keystream generation, substituting the vulnerable mechanical security system with a more robust cryptographic system that ensures message integrity and node security

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If existing security solutions are applied to protect Direct Communication Request messages, then security is provided, but interoperability is lacking and complexity is too high

Engineering Contradiction:
Improvesecurity protectionVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal security solution that works across different scenarios (discovery messages and DCR messages) using a unified key derivation approach, reducing complexity while maintaining security and improving interoperability through a standardized method

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent simplifies the security mechanism by changing parameters such as using a unified keystream generation approach and standardized key selection (DUCK/DUSK), reducing implementation complexity while maintaining security protection

Inventive Principle:
Principle #35Parameter changes

3Reliability

If existing security solutions are used, then short messages can be protected, but long discovery messages longer than 32 bytes cannot be protected

Engineering Contradiction:
Improvesecurity protectionVSAvoidmessage length
Core Design Contradiction:
ReliabilityVSLength of moving object

Solution Approach 1:

The patent applies segmentation by dividing long messages into multiple segments and applying the security mechanism to each segment independently using the key derivation function and keystream, enabling protection of messages of any length while maintaining security integrity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dynamic key derivation that adapts to message length by incorporating freshness values and using configurable parameters, allowing the security mechanism to dynamically adjust to protect both short and long messages effectively

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250008321A1A method for operating a cellular network
Publication Date: 2025.01.02 KONINKLIJKE PHILIPS NV
  • US20250008321A1 patent drawing
  • US20250008321A1 patent drawing
  • US20250008321A1 patent drawing

AI summary

The invention relates to a method for operating a communication system including a. a first station preparing a message including a relay service code indicative of the type of service a user needs for relaying combined with a communication key or an indication of a communication key to be used for communication with a relay station: b. the first station generating a keystream by applying a key derivation function on at least a confidentiality key and freshness value, c. the first station ciphering the message with the key stream.