GPRS SGSN Key Derivation for Mutual Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In GPRS networks, user equipment (UE) lacks the capability for mutual authentication and integrity protection, making it vulnerable to attacks from rogue base stations and algorithm degrading attacks, particularly for high-security communications like Internet of Things (IoT) and machine-to-machine (M2M) communications.

Innovation Solution

A method is introduced where the SGSN device, in conjunction with the HLR/HSS, enhances key management by selecting and deriving ciphering and integrity keys based on UE type indications, enabling mutual authentication and integrity protection by computing intermediate keys and using key derivation functions to generate enhanced ciphering and integrity keys for secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If UE uses SIM card for GPRS network access, then network access is achieved, but only one-way authentication and ciphering protection are available, lacking mutual authentication and integrity protection

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsecurity function completeness
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent changes the security parameters by introducing UE type identification (first type vs. second type) and applying different key derivation methods based on the UE type. For first type UE, the system derives both ciphering key (Kc) and integrity key (Ki) from the authentication key, enabling both ciphering and integrity protection. This parameter-based differentiation resolves the contradiction by providing enhanced security functions specifically for UE types that require them.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If UE uses USIM card for GPRS network access, then two-way authentication is achieved, but only ciphering protection is available, lacking integrity protection

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsecurity function completeness
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent modifies the security configuration by detecting UE type and adjusting the key derivation parameters accordingly. When first type UE is detected, the system enables integrity key derivation in addition to ciphering key derivation, thereby providing both ciphering and integrity protection. This resolves the limitation of USIM-based authentication by adding integrity protection capability through parameter adjustment.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If traditional key derivation method is used, then backward compatibility is maintained, but security vulnerability to algorithm degrading attacks and rogue base station attacks exists

Engineering Contradiction:
ImprovecompatibilityVSAvoidsecurity against attacks
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by providing different security treatments for different UE types. First type UE (vulnerable to attacks) receives enhanced security with integrity protection and improved key derivation, while second type UE continues with traditional methods. This localized enhancement resolves the security vulnerability issue without affecting legacy UE that don't require enhanced protection.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements preliminary action by performing UE type identification early in the authentication process and pre-configuring the appropriate key derivation method before actual communication occurs. This ensures that enhanced security measures are in place before the UE becomes vulnerable to attacks, preventing rather than reacting to security threats.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If enhanced key derivation with integrity protection is implemented for all UE, then security is improved, but system complexity and signaling overhead increase

Engineering Contradiction:
Improvesecurity capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent reduces system complexity by applying enhanced security measures only locally to first type UE rather than universally. The network device identifies UE type and selectively enables integrity key derivation only when needed, avoiding the complexity overhead for legacy second type UE that don't require enhanced security features.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3258718B1GPRS system key enhancement method, SGSN device, UE, HLR/HSS and GPRS system
Publication Date: 2018.12.19 HUAWEI TECH CO LTD
  • EP3258718B1 patent drawingFigure 1
  • EP3258718B1 patent drawingFigure 2
  • EP3258718B1 patent drawingFigure 3

AI summary

This application provides a GPRS system key enhancement method, an SGSN device, UE, an HLR/HSS, and a GPRS system, where the method may include: receiving, by the SGSN, a request message sent by the UE; acquiring, by the SGSN, an authentication vector from the HLR/HSS, where the authentication vector includes a first ciphering key and a first integrity key; if the SGSN determines that the UE is UE of a first type, selecting a ciphering algorithm and an integrity algorithm for the UE, and sending the selected ciphering algorithm and the selected integrity algorithm to the UE; and computing, by the SGSN, a second ciphering key and a second integrity key according to the first ciphering key and the first integrity key. In embodiments of this application, ciphering protection and integrity protection may be performed on a communication message between the SGSN and the UE by using the ciphering algorithm and the integrity algorithm that are selected by the SGSN, the second ciphering key, and the second integrity key, so as to enhance security of communication of UE of the first type in a GPRS network.