Joint Key Generation for Multi-Slice Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In network slicing, managing multiple independent keys for each network slice in a wireless communication system is complex and costly, particularly over the air interface, and poses challenges in authentication and synchronization across different connections.
Innovation Solution
A method that generates a joint key in network nodes, such as RAN and MME, based on the behavior of state transitions of network slices, which is used for both AS and NAS communication, reducing the need for slice-specific keys and enhancing security by leveraging non-deterministic user behavior and system settings.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple independent keys are used for each network slice, then security for each slice is improved, but key management complexity and cost increase
Solution Approach 1:
The patent combines multiple slice-specific keys into a single joint key that is shared across multiple network slices. The joint key is derived from common authentication material and is used for protecting communication on multiple slices, thereby reducing key management complexity while maintaining security through the use of a unified key hierarchy.
Solution Approach 2:
The joint key serves multiple functions across different network slices simultaneously. A single key is used for protecting both AS and NAS communication on multiple slices, making the key management system universal rather than slice-specific, which reduces overhead and simplifies management.
2Reliability
If duplicate control planes and user planes are created for each network slice, then slice-specific security is improved, but bandwidth consumption over the air interface increases
Solution Approach 1:
The patent merges the security functions across multiple slices by using a joint key that protects communication on multiple slices simultaneously. This eliminates the need for separate duplicate control planes and user planes for each slice, thereby reducing bandwidth consumption over the air interface while maintaining security.
3Reliability
If multiple slice-specific keys are used, then authentication security is improved, but synchronization and handover procedures become more complicated
Solution Approach 1:
The patent combines authentication security across slices by using a joint key that is derived from common authentication material. This unified approach simplifies synchronization and handover procedures because the same key is used across multiple slices, eliminating the complexity of coordinating multiple slice-specific keys during these operations.
4Device complexity
If a joint key is used for multiple network slices, then key management complexity is reduced, but the ability to provide slice-specific security is weakened
Solution Approach 1:
The patent segments the key hierarchy into a joint key for common protection and slice-specific derived keys for slice-specific security requirements. The joint key is used for protecting common AS or NAS communication, while slice-specific keys can be derived from it when needed, providing both simplified management and targeted security.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
A method (30) of establishing a key related to at least two network instances (Slice 1, Slice 2) is disclosed performed in a network node (11; 12). The network instances (Slice 1, Slice 2) are used in serving a communication device (14). The method (30) comprises obtaining (31) a first key (KeNB1; KASME1) relating to at least a first network instance (Slice 1); obtaining (32) a second key (KeNB2; KASME2) relating to an additional network instance (Slice 2); determining (33), based on the first key (KeNB1; KASME1) and the second key (KeNB2; KASME2), a joint key (KeNB_joint; KASME_joint) for use in protecting communication with the communication device (14) on the at least first network instance (Slice 1) and on the additional network instance (Slice 2). A method (40) in a communication device (14), network node (11; 12), communication device (14), computer programs and computer program products are also disclosed.