5G KDF Negotiation Mechanism for Secure Key Derivation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The current 5G system lacks support for key derivation function (KDF) negotiation, leading to the use of a single obsolete algorithm, which is difficult and costly to update, and results in weakened security due to the lack of flexible KDF negotiation between user equipment (UE) and network entities, making it vulnerable to bidding down attacks.
Innovation Solution
A method for providing KDF negotiation in a 5G network that involves obtaining UE KDF information, selecting a specific KDF at the core network, and transmitting it to UE and other network functions for security key generation, while also allowing UE to re-negotiate KDF capabilities upon non-agreement, using a prioritized list based on subscriber information and network capabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single KDF (HMAC-SHA-256) is used in the 5G system, then the system architecture remains simple and backward compatible, but security is weakened and algorithm updates become difficult and costly
Solution Approach 1:
The patent implements dynamic KDF selection by introducing a negotiation mechanism where the core network and UE can dynamically agree on different KDFs based on their capabilities. The system transitions from a static single-KDF architecture to a dynamic multi-KDF negotiation framework, allowing algorithms to be selected and changed based on security requirements and device support.
Solution Approach 2:
The patent changes the parameter of KDF selection from fixed to variable. By introducing capability exchange and negotiation protocols, the system allows the KDF parameter to change based on the cryptographic capabilities of the UE and network elements, enabling the use of stronger algorithms like HMAC-SHA-384 or HMAC-SHA-512 when both parties support them.
2Adaptability or versatility
If KDF negotiation is introduced to support multiple algorithms, then flexibility and security are improved, but the complexity of the system increases
Solution Approach 1:
The patent applies preliminary action by having the core network store capability information of UEs in advance. The network elements pre-configure supported KDFs and capability databases, so when authentication is needed, the negotiation can proceed efficiently using pre-stored information rather than requiring complex real-time capability assessment.
Solution Approach 2:
The patent introduces an intermediary mechanism where the core network acts as a mediator between the UE and network elements for KDF selection. The core network receives capability information from UEs, processes it against network capabilities, and facilitates the negotiation, simplifying the interaction complexity.
3Reliability
If network elements are updated to support new KDF algorithms, then security is improved, but the cost and time required for updates increase
Solution Approach 1:
The patent enables dynamic algorithm selection where network elements don't need to be updated for every new algorithm. Instead, the system dynamically negotiates which algorithm to use based on the UE's capabilities and the network's current supported algorithms, allowing gradual deployment without immediate full-system updates.
Solution Approach 2:
The patent allows partial deployment of new KDF algorithms. Network elements can support a subset of algorithms initially, and the negotiation mechanism ensures that only the algorithms both the UE and network support are used. This partial action approach reduces the immediate impact and cost of updates while maintaining security progress.
4Adaptability or versatility
If a common KDF is selected for all security key derivations, then the system remains simple, but flexible key derivation and optimization for specific CPU architectures are lost
Solution Approach 1:
The patent segments the KDF selection process into different phases: initial capability exchange, core network selection based on subscriber information, and final negotiation with network elements. This segmentation allows different KDFs to be selected for different key derivation contexts while maintaining manageable complexity through structured negotiation.
Solution Approach 2:
The patent applies local quality by allowing different KDFs to be selected for different purposes and locations within the 5G system. The core network can select appropriate KDFs based on local subscriber information and network capabilities, enabling optimization for specific CPU architectures or security requirements in different network segments.
Data Source
AI summary
A method for providing a key derivation function (KDF) negotiation in a 5G network is provided. The method which includes: selecting a specific KDF at a UE and at the network for at least one security related key derivation; and transmitting, said selected KDF to the UE and to other network functions to indicate said selected KDF for generating specific security key at a receiver side.


