Fresh Session Key Generation for Wireless Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional wireless communication systems, such as those using the 3GPP AKA protocol, face security risks and efficiency decreases due to the inability to create fresh key material for Network Application Functions (NAFs) without updating existing key material, and ambiguity in managing key material for parallel sessions.

Innovation Solution

A method for generating fresh session keys by using a bootstrapping identifier and random numbers, where user equipment and network application functions contribute to forming session keys using a key derivation function, ensuring secure communication without frequent key updates and clarifying key management for parallel sessions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If key material is updated frequently to prevent replay attacks, then security is improved, but system efficiency deteriorates due to increased HSS traffic and longer UE waiting time

Engineering Contradiction:
ImprovesecurityVSAvoidsystem efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the key material into multiple components: long-term key material stored in HSS and short-term session keys derived locally. This allows frequent session key generation without repeatedly accessing HSS, thus maintaining security while improving efficiency by reducing HSS traffic.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary key derivation by storing multiple pre-computed key material components in the UE and NAF. When a session is needed, fresh session keys are generated by combining these pre-stored components with random values, eliminating the need for frequent HSS updates and reducing waiting time.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If key material is updated frequently to create fresh session keys, then replay attack protection is improved, but loss of time increases due to repeated HSS interactions

Engineering Contradiction:
Improvereplay attack protectionVSAvoidUE waiting time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary key derivation by storing multiple pre-computed key material components in the UE and NAF. When a session is needed, fresh session keys are generated by combining these pre-stored components with random values, eliminating the need for frequent HSS updates and reducing waiting time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables self-service key generation where the UE and NAF can independently derive fresh session keys using locally stored key material components and random values, without requiring HSS intervention for each session, thus reducing both time loss and HSS traffic.

Inventive Principle:
Principle #25Self-service

3Reliability

If the system requires security-aware design to prevent replay attacks, then security is improved, but ease of operation deteriorates as designers must modify NAF to regularly update key material

Engineering Contradiction:
ImprovesecurityVSAvoidease of implementation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables self-service key generation where the UE and NAF can independently derive fresh session keys using locally stored key material components and random values, without requiring HSS intervention for each session, thus reducing both time loss and HSS traffic.

Inventive Principle:
Principle #25Self-service

4Productivity

If the same key material is reused for multiple sessions, then system efficiency is improved, but security deteriorates due to vulnerability to replay attacks

Engineering Contradiction:
Improvesystem efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the key material into multiple components: long-term key material stored in HSS and short-term session keys derived locally. This allows frequent session key generation without repeatedly accessing HSS, thus maintaining security while improving efficiency by reducing HSS traffic.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes parameters by deriving session keys with varying random values for each session, ensuring that even though the base key material remains the same, the resulting session keys are unique and cannot be reused, preventing replay attacks while maintaining system efficiency.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS7558957B2Providing fresh session keys
Publication Date: 2009.07.07 NOKIA OF AMERICA CORP
  • US7558957B2 patent drawing
  • US7558957B2 patent drawing
  • US7558957B2 patent drawing

AI summary

The present invention provides a method of key material generation in which the key material is used to authenticate communication for user equipment and at least one network application function. The method includes providing a bootstrapping identifier associated with first key material and a first random number, receiving information indicative of a second random number, and forming second key material based upon the first key material, the first random number, and the second random number.