Integrated DH Key Agreement and 5G AKA Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity of the Diffie-Hellman (DH) key agreement procedure in existing mobile communication networks increases system design complexity and security risks due to the separation of DH key agreement and 5G Authentication and Key Agreement (AKA) processes.

Innovation Solution

Integrating the DH key agreement procedure with the 5G AKA process by sending a message (N1) that carries DH parameters, including a DH public parameter or index, and an encrypted identifier, to reduce complexity and enhance security by deriving symmetric keys and authentication results within the integrated process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the DH key agreement procedure is performed separately from the 5G AKA authentication procedure, then the security key derivation can be independent and robust, but the system design complexity increases and the authentication process becomes more cumbersome

Engineering Contradiction:
Improvesecurity key derivationVSAvoidsystem design complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the DH key agreement procedure and the 5G AKA authentication procedure into a single integrated authentication process. The SEAF performs both DH key agreement and AKA authentication simultaneously, deriving the root key K from DH shared secret while also executing the AKA challenge-response mechanism. This merging reduces system design complexity while maintaining security through the integration of both cryptographic mechanisms in one unified流程.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If the DH key agreement procedure is performed separately from the 5G AKA authentication procedure, then each procedure can be optimized independently, but the overall authentication time and process length increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges the DH key agreement and AKA authentication into a single integrated process executed by the SEAF. The SEAF receives the UE's DH public key, performs DH key agreement to derive the root key K, and simultaneously executes the AKA authentication challenge-response procedure using the same authentication vector. This combination eliminates the need for separate authentication exchanges, reducing authentication time while maintaining the security benefits of both DH and AKA mechanisms.

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If the DH public key A is not encrypted, then the N1 message can be simpler and transmission faster, but parameter security is compromised and attackers can obtain sensitive information

Engineering Contradiction:
Improvemessage transmission efficiencyVSAvoidparameter security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary encryption to the DH public key A before it is transmitted in the N1 message. The UE encrypts its DH public key A using the network's public key infrastructure before sending it to the SEAF. This preliminary security measure prevents attackers from obtaining the raw DH public key and deriving the root key K, while the encryption overhead is minimal compared to the security benefits gained. The SEAF decrypts the encrypted DH public key to continue the authentication process.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11909869B2Communication method and related product based on key agreement and authentication
Publication Date: 2024.02.20 HUAWEI TECH CO LTD
  • US11909869B2 patent drawing
  • US11909869B2 patent drawing
  • US11909869B2 patent drawing

AI summary

Communication methods and apparatus are described. One communication method includes that user equipment (UE) sends an N1 message to a security anchor function (SEAF), where the N1 message carries a Diffie-Hellman (DH) public parameter or a DH public parameter index, the N1 message further carries an encrypted identifier of the UE, and the encrypted identifier is obtained by encrypting a permanent identifier of the UE and a first DH public key. The UE receives an authentication request that carries a random number and that is sent by the SEAF. The UE sends, to the SEAF, an authentication response used to respond to the authentication request, where the authentication response carries an authentication result calculated based on a root key and the random number.