Centralized Key Management for Cellular Network Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 3GPP cellular network authentication methods require multiple secret keys for various user devices associated with different applications and services, leading to inefficient resource allocation and management across multiple network devices.

Innovation Solution

A central network device generates and stores multiple secret keys for user devices, each valid for a specific duration or geographic area, using a key derivation function and key distribution protocol, allowing efficient authentication and resource allocation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple secret keys are generated and stored by different network devices for different user devices, then authentication security is maintained, but resource allocation efficiency and management complexity deteriorate

Engineering Contradiction:
Improveauthentication securityVSAvoidresource allocation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent consolidates secret key generation and storage functions into a single centralized network device. Multiple secret keys for different user devices are generated and stored centrally rather than distributed across multiple network devices. This merging of functions improves resource allocation efficiency and simplifies management while maintaining authentication security through the centralized key management architecture.

Inventive Principle:
Principle #5Merging (Combining)

2Adaptability or versatility

If multiple network devices store secret keys for various user devices, then authentication capability is provided, but device complexity and management difficulty increase

Engineering Contradiction:
Improveauthentication capabilityVSAvoidmanagement complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the secret key generation and storage functionality from multiple distributed network devices and consolidates it into a single centralized network device. This extraction reduces the complexity burden on individual network devices and simplifies overall system management, while the centralized device maintains the necessary authentication capability for multiple user devices across different applications and services.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If secret keys are generated by distributed network devices, then local authentication is enabled, but resource allocation efficiency deteriorates

Engineering Contradiction:
Improvelocal authenticationVSAvoidresource allocation efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The centralized network device is designed to perform multiple authentication functions for different user devices, applications, and services simultaneously. This universal authentication capability enables the system to maintain local authentication effectiveness while improving overall resource allocation efficiency by consolidating key management operations in a single multi-functional device rather than distributing them across multiple single-purpose devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8990555B2Centralized key management
Publication Date: 2015.03.24 VERIZON PATENT & LICENSING INC
  • US8990555B2 patent drawing
  • US8990555B2 patent drawing
  • US8990555B2 patent drawing

AI summary

A first network device is configured to receive a first request for a first secret key, generate the first secret key, and send the first secret key to a second network device and a first user device; and is also configured to receive a second request for a second secret key, generate the second secret key, and send the second secret key to a third network device and a second user device. The second network device and the first user device may mutually authenticate each other using the first secret key. The third network device and the second user device may mutually authenticate each other using second secret key.