Digital Asset Container Key Management for 5G Metaverse Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G systems lack mechanisms for securely storing and managing digital assets and authorizing their retrieval, particularly in the context of metaverse services, where sensitive information requires higher security levels.

Innovation Solution

The introduction of a Digital Asset Container (DAC) network function that generates and manages keys for encrypting and decrypting digital assets, using user-specific parameters and key derivation functions to ensure secure storage and authorized access, with mechanisms for key freshness and document-specific encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital assets are stored in current 5G systems, then storage capability is provided, but security and authorization mechanisms are insufficient

Engineering Contradiction:
ImprovesecurityVSAvoidauthorization mechanism
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments digital assets into encrypted containers with separate key management. Each digital asset is encrypted with its own key, and keys are managed separately by the authentication function, creating modular security units that can be individually controlled and authorized.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication function acts as an intermediary between entities and digital assets. It receives authorization requests, verifies credentials, and provides decryption keys only to authorized entities, mediating access control without exposing the actual digital assets or keys to unauthorized parties.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption keys are generated using key derivation functions, then security is enhanced, but key management complexity increases

Engineering Contradiction:
Improveencryption securityVSAvoidkey management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The key management system is self-service in that keys are automatically derived from user credentials through key derivation functions. The authentication function autonomously generates and manages encryption keys based on user authentication data, eliminating the need for manual key distribution and reducing management overhead.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If document-specific encryption is implemented, then security precision is improved, but processing overhead increases

Engineering Contradiction:
Improveauthorization precisionVSAvoidprocessing speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

Digital assets are pre-encrypted with document-specific keys before storage. The encryption keys are derived in advance from user credentials, and the encrypted assets are stored ready for retrieval. This preliminary encryption eliminates the need for real-time key generation during access, reducing processing overhead at retrieval time.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240422533A1Apparatus, method, and computer program
Publication Date: 2024.12.19 NOKIA TECHNOLOGIES OY
  • US20240422533A1 patent drawing
  • US20240422533A1 patent drawing
  • US20240422533A1 patent drawing

AI summary

There is provided an apparatus, method, and computer program for causing an apparatus for a user equipment to perform: encrypting a digital asset using a first key to form an encrypted digital asset; providing the encrypted digital asset and an index for the encrypted digital asset to a first network function; and providing an identification of the encrypted digital asset to a first entity.