Fresh Session Key Generation for Wireless Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional wireless communication systems, such as those using the 3GPP AKA protocol, face security risks and efficiency decreases due to the inability to create fresh key material for Network Application Functions (NAFs) without updating existing key material, and ambiguity in managing key material for parallel sessions.
Innovation Solution
A method for generating fresh session keys by using a bootstrapping identifier and random numbers, where user equipment and network application functions contribute to forming session keys using a key derivation function, ensuring secure communication without frequent key updates and clarifying key management for parallel sessions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If key material is updated frequently to prevent replay attacks, then security is improved, but system efficiency deteriorates due to increased HSS traffic and longer UE waiting time
Solution Approach 1:
The patent segments the key material into multiple components: long-term key material stored in HSS and short-term session keys derived locally. This allows frequent session key generation without repeatedly accessing HSS, thus maintaining security while improving efficiency by reducing HSS traffic.
Solution Approach 2:
The patent performs preliminary key derivation by storing multiple pre-computed key material components in the UE and NAF. When a session is needed, fresh session keys are generated by combining these pre-stored components with random values, eliminating the need for frequent HSS updates and reducing waiting time.
2Reliability
If key material is updated frequently to create fresh session keys, then replay attack protection is improved, but loss of time increases due to repeated HSS interactions
Solution Approach 1:
The patent performs preliminary key derivation by storing multiple pre-computed key material components in the UE and NAF. When a session is needed, fresh session keys are generated by combining these pre-stored components with random values, eliminating the need for frequent HSS updates and reducing waiting time.
Solution Approach 2:
The patent enables self-service key generation where the UE and NAF can independently derive fresh session keys using locally stored key material components and random values, without requiring HSS intervention for each session, thus reducing both time loss and HSS traffic.
3Reliability
If the system requires security-aware design to prevent replay attacks, then security is improved, but ease of operation deteriorates as designers must modify NAF to regularly update key material
Solution Approach 1:
The patent enables self-service key generation where the UE and NAF can independently derive fresh session keys using locally stored key material components and random values, without requiring HSS intervention for each session, thus reducing both time loss and HSS traffic.
4Productivity
If the same key material is reused for multiple sessions, then system efficiency is improved, but security deteriorates due to vulnerability to replay attacks
Solution Approach 1:
The patent segments the key material into multiple components: long-term key material stored in HSS and short-term session keys derived locally. This allows frequent session key generation without repeatedly accessing HSS, thus maintaining security while improving efficiency by reducing HSS traffic.
Solution Approach 2:
The patent changes parameters by deriving session keys with varying random values for each session, ensuring that even though the base key material remains the same, the resulting session keys are unique and cannot be reused, preventing replay attacks while maintaining system efficiency.
Data Source
AI summary
The present invention provides a method of key material generation in which the key material is used to authenticate communication for user equipment and at least one network application function. The method includes providing a bootstrapping identifier associated with first key material and a first random number, receiving information indicative of a second random number, and forming second key material based upon the first key material, the first random number, and the second random number.


