Wireless Authentication Using Encrypted Key Encryption Key
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless communication systems, particularly in LTE networks, face vulnerabilities in security configurations that can lead to attacks such as impersonation and unauthorized access, especially with the deployment of newer technologies like 5G and the increased use of less secure environments for network functions.
Innovation Solution
A method is introduced where a user equipment (UE) establishes a connection with a serving network by transmitting an authentication credential, including a randomly selected key encryption key (KEK) and serving network identifier, which is encrypted using a Home Subscriber Server (HSS) encryption key. This credential is then decrypted and verified by a Mobility Management Entity (MME) and HSS, ensuring only authorized network nodes can authenticate and establish secure connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods are used in LTE networks, then existing communication functionality is maintained, but security vulnerabilities arise allowing impersonation and unauthorized access attacks
Solution Approach 1:
The UE performs preliminary actions by selecting and encrypting a random KEK with the HSS encryption key before transmitting authentication credentials to the MME. This pre-encryption of the KEK ensures that the key material is protected before it even enters the authentication exchange, preventing interception and misuse by attackers
Solution Approach 2:
The HSS encryption key acts as an intermediary that the UE uses to encrypt the KEK. This intermediary mechanism allows the UE to establish a secure connection with the HSS without directly sharing the HSS encryption key with the MME, thereby preventing key exposure while enabling authentication
2Adaptability or versatility
If security configuration is performed using traditional key derivation methods, then compatibility with existing LTE standards is maintained, but vulnerabilities are exposed in the security configuration process
Solution Approach 1:
The authentication process is segmented into distinct phases: (1) UE selects and encrypts random KEK with HSS encryption key, (2) MME receives and processes the encrypted credential, (3) HSS verifies the credential and establishes secure connection. This segmentation allows each phase to be optimized for security while maintaining overall LTE standard compatibility
Solution Approach 2:
The patent changes the parameter of key encryption from traditional methods to using the HSS encryption key specifically for encrypting the KEK. This parameter change enhances security by ensuring that the KEK is protected by a strong, centralized key management mechanism while still working within the LTE authentication framework
3Ease of operation
If the UE transmits authentication credentials without pre-encryption using HSS key, then the authentication process is simpler, but the credentials are vulnerable to interception and misuse
Solution Approach 1:
The UE performs preliminary encryption of the KEK with the HSS encryption key before transmitting authentication credentials to the MME. This pre-encryption ensures that even if credentials are intercepted during transmission, the encrypted KEK cannot be decrypted or misused without the HSS encryption key
Solution Approach 2:
The UE applies preliminary anti-action by encrypting the KEK with the HSS encryption key before transmission. This preemptive security measure counteracts potential interception and decryption attacks by ensuring that the credentials are already protected against unauthorized access before they leave the UE
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method, an apparatus, and a computer program product for wireless communication are provided. The method may include establishing a connection with a serving network, transmitting an encrypted authentication credential that includes a randomly selected key encryption key (KEK) and a serving network identifier to the serving network, receiving authentication information and a signature from the serving network, and authenticating the serving network by verifying the signature based on the KEK. The encrypted authentication credential may be operative to identify the serving network. The signature may be generated using the KEK.