Wireless Authentication Using Encrypted Key Encryption Key

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication systems, particularly in LTE networks, face vulnerabilities in security configurations that can lead to attacks such as impersonation and unauthorized access, especially with the deployment of newer technologies like 5G and the increased use of less secure environments for network functions.

Innovation Solution

A method is introduced where a user equipment (UE) establishes a connection with a serving network by transmitting an authentication credential, including a randomly selected key encryption key (KEK) and serving network identifier, which is encrypted using a Home Subscriber Server (HSS) encryption key. This credential is then decrypted and verified by a Mobility Management Entity (MME) and HSS, ensuring only authorized network nodes can authenticate and establish secure connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used in LTE networks, then existing communication functionality is maintained, but security vulnerabilities arise allowing impersonation and unauthorized access attacks

Engineering Contradiction:
ImprovesecurityVSAvoidimpersonation attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The UE performs preliminary actions by selecting and encrypting a random KEK with the HSS encryption key before transmitting authentication credentials to the MME. This pre-encryption of the KEK ensures that the key material is protected before it even enters the authentication exchange, preventing interception and misuse by attackers

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The HSS encryption key acts as an intermediary that the UE uses to encrypt the KEK. This intermediary mechanism allows the UE to establish a secure connection with the HSS without directly sharing the HSS encryption key with the MME, thereby preventing key exposure while enabling authentication

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If security configuration is performed using traditional key derivation methods, then compatibility with existing LTE standards is maintained, but vulnerabilities are exposed in the security configuration process

Engineering Contradiction:
ImprovecompatibilityVSAvoidsecurity configuration
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The authentication process is segmented into distinct phases: (1) UE selects and encrypts random KEK with HSS encryption key, (2) MME receives and processes the encrypted credential, (3) HSS verifies the credential and establishes secure connection. This segmentation allows each phase to be optimized for security while maintaining overall LTE standard compatibility

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter of key encryption from traditional methods to using the HSS encryption key specifically for encrypting the KEK. This parameter change enhances security by ensuring that the KEK is protected by a strong, centralized key management mechanism while still working within the LTE authentication framework

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If the UE transmits authentication credentials without pre-encryption using HSS key, then the authentication process is simpler, but the credentials are vulnerable to interception and misuse

Engineering Contradiction:
Improveauthentication processVSAvoidcredential interception
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The UE performs preliminary encryption of the KEK with the HSS encryption key before transmitting authentication credentials to the MME. This pre-encryption ensures that even if credentials are intercepted during transmission, the encrypted KEK cannot be decrypted or misused without the HSS encryption key

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The UE applies preliminary anti-action by encrypting the KEK with the HSS encryption key before transmission. This preemptive security measure counteracts potential interception and decryption attacks by ensuring that the credentials are already protected against unauthorized access before they leave the UE

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentEP3198906B1Serving network authentication
Publication Date: 2020.07.15 QUALCOMM INC
  • EP3198906B1 patent drawingFigure 1
  • EP3198906B1 patent drawingFigure 2
  • EP3198906B1 patent drawingFigure 3

AI summary

A method, an apparatus, and a computer program product for wireless communication are provided. The method may include establishing a connection with a serving network, transmitting an encrypted authentication credential that includes a randomly selected key encryption key (KEK) and a serving network identifier to the serving network, receiving authentication information and a signature from the serving network, and authenticating the serving network by verifying the signature based on the KEK. The encrypted authentication credential may be operative to identify the serving network. The signature may be generated using the KEK.