Cryptographic Key Binding for Roaming Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems face challenges in protecting cryptographic keys when a communication device roams between networks, especially when authenticating to a non-public network through an intermediate network, as the key binding to the visited network may not be sufficient to prevent malicious reuse.
Innovation Solution
Generating a cryptographic key as a function of information bound to the intermediate communication network, which is then used for integrity and confidentiality protection, effectively binding the key to the intermediate network and preventing its malicious reuse across different networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the cryptographic key is bound to the visited network, then the key can be used for communication in the visited network, but the key may be stolen and maliciously re-used to eavesdrop on communications with a different visited network
Solution Approach 1:
The patent applies local quality by binding the cryptographic key to specific network identifiers (PLMN ID, NPN ID, SNN) so that the key's security properties are localized to the specific network context. The key derivation function incorporates these identifiers, ensuring that a key generated for one network cannot be maliciously reused in another network, thus preventing eavesdropping while maintaining key usability in the authorized network
2Object-affected harmful factors
If the cryptographic key is bound to the intermediate network, then the key cannot be maliciously re-used for eavesdropping, but the key binding to the visited network becomes insufficient
Solution Approach 1:
The patent merges multiple network identifiers (intermediate network's PLMN ID, NPN ID, and serving network's SNN) into a single key derivation process. This combination ensures that the cryptographic key is simultaneously bound to both the intermediate network and the visited network, providing reliable key binding that prevents malicious reuse while maintaining sufficiency for communication protection in the visited network
3Adaptability or versatility
If the communication device authenticates to a non-public network via a home public network, then the device can access the NPN, but the key binding to the public network may not be sufficient for NPN security
Solution Approach 1:
The patent applies parameter changes by modifying the key derivation parameters to include not only the public network identifiers but also the non-public network identifiers (NPN ID, network slice information). This changes the key's binding parameters from solely public network-based to a composite of public and private network identifiers, ensuring that the key is sufficiently bound to the NPN context while maintaining the device's ability to authenticate via the home public network
Data Source
AI summary
A communication device (2) generates a cryptographic key (20K) as a function of information (20B) bound to an intermediate communication network (20) via which the communication device (2) authenticates a subscription to a subscribed communication network (10). Here, the communication device (2) is served by a serving communication network (30) that differs from the intermediate communication network (20). The communication device (2) protects communication for the communication device (2) based on the generated cryptographic key (20K).


