Joint Private Key Generation for Telecom Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods for terminal devices in the telecom industry rely on symmetric key systems, where the telecom operator controls the authentication key, compromising network security and limiting vertical industry customers' ability to select operation networks.

Innovation Solution

A private key generation method involving a first and second network device, where each generates a sub-private key based on a parameter set, and these are synthesized into a joint private key, ensuring trust by both the telecom operator and the vertical industry customer without being controlled by the telecom operator.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a symmetric key system is used where the telecom operator controls the authentication key, then the telecom operator can easily manage authentication, but the security of digital assets of vertical industry customers cannot be ensured

Engineering Contradiction:
Improveauthentication managementVSAvoidsecurity of digital assets
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication key is segmented into two parts: a first key part generated and controlled by the terminal device, and a second key part generated and controlled by the authentication server. These two key parts are combined to form the complete authentication key. This segmentation allows the terminal device to have control over part of the key, improving security while the authentication server manages the overall authentication process.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from a symmetric key system to an asymmetric key system where the terminal device and authentication server have different roles and control different parts of the key. The terminal device generates its own public-private key pair, and the authentication server generates another key pair. This asymmetric structure enables the terminal device to have autonomous control while the server provides authentication services.

Inventive Principle:
Principle #4Asymmetry

2Device complexity

If the authentication key is completely controlled by the telecom operator, then the operator can simplify key management, but vertical industry customers cannot make informed network selection decisions

Engineering Contradiction:
Improvekey management complexityVSAvoidnetwork selection capability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The terminal device performs preliminary actions by generating its own public-private key pair before authentication with the server. The terminal device's public key is registered with the authentication server in advance. This preliminary key generation and registration enables the terminal device to have autonomous control over its authentication credentials, allowing it to make informed network selection decisions while the server maintains manageable key storage.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3570487B1Private key generation method, device and system
Publication Date: 2021.08.25 HUAWEI TECH CO LTD
  • EP3570487B1 patent drawingFigure 1~2
  • EP3570487B1 patent drawingFigure 3A
  • EP3570487B1 patent drawingFigure 3B

AI summary

This application discloses a private key generation method and system, and a device. The method includes: sending, by a first network device, a first request to a second network device, where the first request includes a first parameter set; receiving, by the first network device, a first response message returned by the second network device, where the first response message includes a first sub-private key and a second parameter set, the first sub-private key is generated based on the first parameter set, and the first sub-private key is generated for a terminal device; generating, by the first network device, a second sub-private key based on the second parameter set, where the second sub-private key is generated for the terminal device; and synthesizing, by the first network device, the first sub-private key and the second sub-private key into a joint private key according to a synthesis formula. According to the foregoing method, a private key that is trusted by both a telecom operator and a vertical industry customer but is not controlled by the telecom operator can be generated.