Cellular Network Security Key Segmentation via EAP

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless communication systems, the same master session key (MSK) derived during an Extensible Authentication Protocol (EAP) procedure can be compromised when accessed through both cellular and non-cellular networks, allowing attackers to impersonate the cellular network, compromising security.

Innovation Solution

The method involves determining the type of network associated with the authenticator and performing authentication procedures using either the MSK or Extended MSK (EMSK) based on the network type, ensuring that the correct security keys are derived and used for each network type, preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the same MSK is used for both cellular and non-cellular networks, then authentication versatility is improved, but security is worsened due to potential compromise through non-cellular networks

Engineering Contradiction:
Improveauthentication versatilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the master session key into two separate keys: MSK for non-cellular networks and EMSK for cellular networks. This segmentation ensures that compromise of one key does not affect the other, resolving the security vulnerability while maintaining authentication capability across both network types.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by assigning different security key properties to different network types. Non-cellular networks use MSK with specific derivation parameters, while cellular networks use EMSK with different parameters. This localized key differentiation enhances security for each specific network context.

Inventive Principle:
Principle #3Local quality

2Reliability

If separate security keys are derived for cellular and non-cellular networks, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary action by deriving both MSK and EMSK during the initial EAP authentication process. This allows the system to have both security keys ready in advance, avoiding the need for separate authentication processes later and reducing operational complexity despite the additional key derivation step.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent makes the EAP authentication mechanism universal by enabling it to serve both cellular and non-cellular networks through a single authentication framework that derives both MSK and EMSK. This multi-functionality allows one authentication process to support multiple network types with appropriate key differentiation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12022279B2Techniques for deriving security keys for a cellular network based on performance of an extensible authentication protocol (EAP) procedure
Publication Date: 2024.06.25 QUALCOMM INC
  • US12022279B2 patent drawing
  • US12022279B2 patent drawing
  • US12022279B2 patent drawing

AI summary

Techniques are described for wireless communication. A method for wireless communication at a user equipment (UE) includes performing an extensible authentication protocol (EAP) procedure with an authentication server via an authenticator. The EAP procedure is based at least in part on a set of authentication credentials exchanged between the UE and the authentication server. The method also includes deriving, as part of performing the EAP procedure, a master session key (MSK) and an extended master session key (EMSK) that are based at least in part on the authentication credentials and a first set of parameters; determining a network type associated with the authenticator; and performing, based at least in part on the determined network type, at least one authentication procedure with the authenticator. The at least one authentication procedure is based on an association of the MSK or the EMSK with the determined network type.