Home Network Security Endpoint Key Derivation Without CK and IK

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The 4G battery efficient security solution for low-throughput machine type communication devices is not fully applicable to the 5G network architecture due to the inability of the home public land mobile network security endpoint to obtain the cipher key and integrity key of the user equipment, leading to increased data security risks.

Innovation Solution

A communication method and apparatus that enables the home network security endpoint to derive a security key by using a first identifier of the user equipment, generating a second key based on a cipher key, integrity key, and additional information without directly obtaining the cipher and integrity keys, applicable to 5G network architectures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Use of energy by moving object

If the home network security endpoint uses the 4G BEST authentication manner to derive security keys, then battery efficiency is improved, but data security is worsened because the HSE cannot obtain CK and IK in 5G architecture

Engineering Contradiction:
Improvebattery efficiencyVSAvoiddata security
Core Design Contradiction:
Use of energy by moving objectVSReliability

Solution Approach 1:

The patent introduces a first network function as an intermediary between the HSE and the key management system. This intermediary generates a first key based on CK, IK, and first information, then provides it to the HSE. The HSE uses this first key to derive the second key without directly accessing CK and IK, thus maintaining security while enabling the BEST authentication flow in 5G architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the home network security endpoint directly obtains CK and IK to derive security keys, then key derivation simplicity is improved, but security is worsened due to direct exposure of sensitive keys

Engineering Contradiction:
Improvekey derivation simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the sensitive CK and IK from the key derivation process by having the first network function generate a first key that incorporates these secrets without exposing them to the HSE. The HSE only receives and processes the first key, which contains the necessary cryptographic material derived from CK and IK but does not reveal them, thus simplifying HSE operations while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If the 5G architecture is adopted to improve network capabilities, then network performance is improved, but compatibility with 4G BEST solution is worsened

Engineering Contradiction:
Improvenetwork performanceVSAvoidcompatibility
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal key derivation mechanism that works across both 4G and 5G architectures. The first network function acts as a multi-functional element that can operate in 5G environments while replicating the security behavior of the 4G HSE. This allows the BEST authentication manner to function in 5G networks with the same battery efficiency and security properties as in 4G, achieving backward compatibility without sacrificing forward performance.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12413963B2Communication method and apparatus
Publication Date: 2025.09.09 HUAWEI TECH CO LTD
  • US12413963B2 patent drawing
  • US12413963B2 patent drawing
  • US12413963B2 patent drawing

AI summary

A communication method and apparatus are provided. The method includes: A home network security endpoint receives a first request from user equipment, where the first request includes a first identifier of the user equipment. The home network security endpoint then send a second request to a first network function, where the second request includes a second identifier of the user equipment, and receive a first key from the first network function, where the first key is generated based on a cipher key, an integrity key, and a name of a serving network of the user equipment. The home network security endpoint may generate a second key based on the first key, where the second key includes an encryption protection key and/or an integrity protection key.