Edge Enabler Client Key Derivation for Wireless Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The reuse of derived keys in wireless communications networks for multiple edge configuration servers and edge enabler servers poses security issues.

Innovation Solution

A method and apparatus for deriving a unique key (KAFEEC) based on an edge enabler client identifier (EEC-ID), which includes receiving a request message from an edge server function containing an edge server identifier and an EEC-ID, and then deriving the KAFEEC using the edge server identifier and the EEC-ID.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a derived key is reused for multiple edge configuration servers and edge enabler servers, then key management complexity is reduced, but security is compromised

Engineering Contradiction:
Improvekey management complexityVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the key management system by introducing a key derivation function that generates unique keys for each edge server function. Instead of using a single shared derived key, the system now derives separate keys (KAFEEC) for each edge server function using the edge server identifier and edge enabler client identifier as inputs. This segmentation eliminates the security risk of key reuse while maintaining manageable complexity through automated key derivation.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a unique key is derived for each edge server function, then security is enhanced, but key management complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service key management through automated key derivation. The network function automatically derives the unique key (KAFEEC) for each edge server function using the key derivation function with inputs including the edge server identifier and edge enabler client identifier. This eliminates the need for manual key distribution and management, reducing operational complexity despite the increase in unique keys. The encrypted EEC-ID mechanism also automates the protection of identifiers during transmission.

Inventive Principle:
Principle #25Self-service

3Reliability

If an encrypted EEC-ID is transmitted, then security is improved, but processing overhead increases

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by encrypting the edge enabler client identifier (EEC-ID) using the KAFEEC key before transmission to the network function. This encryption transforms the plaintext identifier into ciphertext, ensuring that even if intercepted, the identifier cannot be used to derive keys or compromise security. The processing overhead is justified by the significant security enhancement, as the encrypted identifier prevents unauthorized key derivation and protects client identity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12273707B2Deriving a key based on an edge enabler client identifier
Publication Date: 2025.04.08 LENOVO (SINGAPORE) PTE LTD
  • US12273707B2 patent drawing
  • US12273707B2 patent drawing
  • US12273707B2 patent drawing

AI summary

Apparatuses, methods, and systems are disclosed for deriving a key based on an edge enabler client identifier. One method includes receiving, at a network function, a request message from an edge server function. The request message includes: an edge server identifier; and an edge enabler client identifier (EEC-ID), wherein the EEC-ID includes: an unencrypted EEC-ID; or an encrypted EEC-ID. The encrypted EEC-ID is encrypted with an authentication and key management (AKMA) key (KAKMA). The method includes deriving a unique key (KAFEEC) based on the edge server identifier and the EEC-ID. The method includes transmitting a response message to the edge server function. The response message includes: the KAFEEC; and an unencrypted EEC-ID.