Joint Key Generation for Multi-Slice Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In network slicing, managing multiple independent keys for each network slice in a wireless communication system is complex and costly, particularly over the air interface, and poses challenges in authentication and synchronization across different connections.

Innovation Solution

A method that generates a joint key in network nodes, such as RAN and MME, based on the behavior of state transitions of network slices, which is used for both AS and NAS communication, reducing the need for slice-specific keys and enhancing security by leveraging non-deterministic user behavior and system settings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple independent keys are used for each network slice, then security for each slice is improved, but key management complexity and cost increase

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple slice-specific keys into a single joint key that is shared across multiple network slices. The joint key is derived from common authentication material and is used for protecting communication on multiple slices, thereby reducing key management complexity while maintaining security through the use of a unified key hierarchy.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The joint key serves multiple functions across different network slices simultaneously. A single key is used for protecting both AS and NAS communication on multiple slices, making the key management system universal rather than slice-specific, which reduces overhead and simplifies management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If duplicate control planes and user planes are created for each network slice, then slice-specific security is improved, but bandwidth consumption over the air interface increases

Engineering Contradiction:
Improveslice-specific securityVSAvoidbandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent merges the security functions across multiple slices by using a joint key that protects communication on multiple slices simultaneously. This eliminates the need for separate duplicate control planes and user planes for each slice, thereby reducing bandwidth consumption over the air interface while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If multiple slice-specific keys are used, then authentication security is improved, but synchronization and handover procedures become more complicated

Engineering Contradiction:
Improveauthentication securityVSAvoidsynchronization complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines authentication security across slices by using a joint key that is derived from common authentication material. This unified approach simplifies synchronization and handover procedures because the same key is used across multiple slices, eliminating the complexity of coordinating multiple slice-specific keys during these operations.

Inventive Principle:
Principle #5Merging (Combining)

4Device complexity

If a joint key is used for multiple network slices, then key management complexity is reduced, but the ability to provide slice-specific security is weakened

Engineering Contradiction:
Improvekey management complexityVSAvoidslice-specific security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the key hierarchy into a joint key for common protection and slice-specific derived keys for slice-specific security requirements. The joint key is used for protecting common AS or NAS communication, while slice-specific keys can be derived from it when needed, providing both simplified management and targeted security.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3403367B1Methods, nodes and communication device for establishing a key related to at least two network instances
Publication Date: 2019.09.18 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP3403367B1 patent drawingFigure 1~2
  • EP3403367B1 patent drawingFigure 3
  • EP3403367B1 patent drawingFigure 4

AI summary

A method (30) of establishing a key related to at least two network instances (Slice 1, Slice 2) is disclosed performed in a network node (11; 12). The network instances (Slice 1, Slice 2) are used in serving a communication device (14). The method (30) comprises obtaining (31) a first key (KeNB1; KASME1) relating to at least a first network instance (Slice 1); obtaining (32) a second key (KeNB2; KASME2) relating to an additional network instance (Slice 2); determining (33), based on the first key (KeNB1; KASME1) and the second key (KeNB2; KASME2), a joint key (KeNB_joint; KASME_joint) for use in protecting communication with the communication device (14) on the at least first network instance (Slice 1) and on the additional network instance (Slice 2). A method (40) in a communication device (14), network node (11; 12), communication device (14), computer programs and computer program products are also disclosed.