IAB Relay Dynamic PSK Generation for 5G F1 Interface Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G IAB relay devices require pre-configuration of security credentials for IKEv2 PSK authentication, leading to increased manufacturing costs, management efforts, and latency in setting up secure connections, especially in scenarios where ad-hoc and temporary configurations are needed.

Innovation Solution

The method involves dynamically generating a Pre-Shared Key (PSK) for IKEv2 authentication at the IAB relay device, eliminating the need for pre-configuration, by deriving a stratum security key and using it to compute the PSK for mutual authentication and establishing a secure F1 interface.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If pre-configuration of security credentials is used for IKEv2 PSK authentication, then authentication security is maintained, but manufacturing costs and management efforts increase

Engineering Contradiction:
Improveauthentication securityVSAvoidmanufacturing cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The IAB relay device automatically generates its own PSK using the derived stratum security key without requiring external pre-configuration. The device serves itself by computing the PSK locally through cryptographic operations based on already-held credentials, eliminating the need for manual or automated pre-provisioning processes

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent transforms the static pre-configured PSK parameter into a dynamic parameter that is derived on-demand from the stratum security key. This parameter change allows the system to maintain security while eliminating the need for pre-configuration storage and management

Inventive Principle:
Principle #35Parameter changes

2Reliability

If pre-configuration of security credentials is used for IKEv2 PSK authentication, then authentication security is maintained, but latency in setting up secure connections increases

Engineering Contradiction:
Improveauthentication securityVSAvoidconnection setup latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The stratum security key is derived in advance during the RRC connection setup or security context establishment phase, before the IKEv2 authentication is needed. This preliminary derivation of the base key material enables rapid PSK generation when authentication is required, eliminating the latency of on-the-fly key generation or retrieval

Inventive Principle:
Principle #10Preliminary action

3Reliability

If pre-configuration of security credentials is used for IKEv2 PSK authentication, then authentication functionality is ensured, but management efforts increase

Engineering Contradiction:
Improveauthentication functionalityVSAvoidmanagement effort
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The device autonomously manages its authentication credentials by automatically deriving the PSK from the stratum security key whenever needed. This self-service approach eliminates the need for external management systems to provision, update, or revoke PSKs, significantly reducing operational management efforts

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes the PSK from a static pre-configured parameter requiring management to a dynamically derived parameter that is automatically regenerated from the stratum security key, transforming it from a managed asset to an on-demand computation

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3751817B1Method of dynamically provisioning a key for authentication in relay device
Publication Date: 2025.03.19 SAMSUNG ELECTRONICS CO LTD
  • EP3751817B1 patent drawingFigure 1A
  • EP3751817B1 patent drawingFigure 1B
  • EP3751817B1 patent drawingFigure 2

AI summary

The present disclosure relates to a communication method and system for converging a 5th-Generation (5G) communication system for supporting higher data rates beyond a 4th-Generation (4G) system with a technology for Internet of Things (IoT). The present disclosure may be applied to intelligent services based on the 5G communication technology and the IoT-related technology, such as smart home, smart building, smart city, smart car, connected car, health care, digital education, smart retail, security and safety services. Embodiments herein provide a method for authentication by dynamically generating security credentials in plug and play scenarios without a pre-configuration of Fl security credentials at an integrated access and backhaul (IAB) relay device in a wireless network. The method includes generating, by the IAB relay device, a stratum security key for one of an access stratums (AS) security establishment and a non-access stratums (NAS) security establishment with an IAB donor device in the wireless network. Further, the method includes generating, by the IAB relay device, a pre-shared key (PSK) based on the stratum security key. Further, the method includes generating an Internet Key Exchange (IKE) value using the PSK for establishing an Fl interface security with the IAB donor device.