IAB Relay Dynamic PSK Generation for 5G F1 Interface Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 5G IAB relay devices require pre-configuration of security credentials for IKEv2 PSK authentication, leading to increased manufacturing costs, management efforts, and latency in setting up secure connections, especially in scenarios where ad-hoc and temporary configurations are needed.
Innovation Solution
The method involves dynamically generating a Pre-Shared Key (PSK) for IKEv2 authentication at the IAB relay device, eliminating the need for pre-configuration, by deriving a stratum security key and using it to compute the PSK for mutual authentication and establishing a secure F1 interface.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If pre-configuration of security credentials is used for IKEv2 PSK authentication, then authentication security is maintained, but manufacturing costs and management efforts increase
Solution Approach 1:
The IAB relay device automatically generates its own PSK using the derived stratum security key without requiring external pre-configuration. The device serves itself by computing the PSK locally through cryptographic operations based on already-held credentials, eliminating the need for manual or automated pre-provisioning processes
Solution Approach 2:
The patent transforms the static pre-configured PSK parameter into a dynamic parameter that is derived on-demand from the stratum security key. This parameter change allows the system to maintain security while eliminating the need for pre-configuration storage and management
2Reliability
If pre-configuration of security credentials is used for IKEv2 PSK authentication, then authentication security is maintained, but latency in setting up secure connections increases
Solution Approach 1:
The stratum security key is derived in advance during the RRC connection setup or security context establishment phase, before the IKEv2 authentication is needed. This preliminary derivation of the base key material enables rapid PSK generation when authentication is required, eliminating the latency of on-the-fly key generation or retrieval
3Reliability
If pre-configuration of security credentials is used for IKEv2 PSK authentication, then authentication functionality is ensured, but management efforts increase
Solution Approach 1:
The device autonomously manages its authentication credentials by automatically deriving the PSK from the stratum security key whenever needed. This self-service approach eliminates the need for external management systems to provision, update, or revoke PSKs, significantly reducing operational management efforts
Solution Approach 2:
The patent changes the PSK from a static pre-configured parameter requiring management to a dynamically derived parameter that is automatically regenerated from the stratum security key, transforming it from a managed asset to an on-demand computation
Data Source
Figure 1A
Figure 1B
Figure 2
AI summary
The present disclosure relates to a communication method and system for converging a 5th-Generation (5G) communication system for supporting higher data rates beyond a 4th-Generation (4G) system with a technology for Internet of Things (IoT). The present disclosure may be applied to intelligent services based on the 5G communication technology and the IoT-related technology, such as smart home, smart building, smart city, smart car, connected car, health care, digital education, smart retail, security and safety services. Embodiments herein provide a method for authentication by dynamically generating security credentials in plug and play scenarios without a pre-configuration of Fl security credentials at an integrated access and backhaul (IAB) relay device in a wireless network. The method includes generating, by the IAB relay device, a stratum security key for one of an access stratums (AS) security establishment and a non-access stratums (NAS) security establishment with an IAB donor device in the wireless network. Further, the method includes generating, by the IAB relay device, a pre-shared key (PSK) based on the stratum security key. Further, the method includes generating an Internet Key Exchange (IKE) value using the PSK for establishing an Fl interface security with the IAB donor device.