Cryptographic Key Derivation for Mobile Radio Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In mobile radio systems, the existing key infrastructure based on symmetrical keys for IMS AKA authentication does not adequately secure communication between mobile radio terminals and application servers, as the integrity and transfer keys can compromise security if directly shared with application servers or visited networks, and modifying protocols is costly and complex.
Innovation Solution
A method to derive new cryptographic keys from the integrity and transfer keys within the mobile radio terminal and home communications network, using a key derivation function that prevents inference back to the original keys, ensuring secure communication without modifying existing protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If integrity key and transfer key are directly shared with application servers or visited networks, then communication security is simplified, but cryptographic security is compromised
Solution Approach 1:
The patent segments the original authentication key material into multiple derived session keys, each dedicated to specific communication contexts (e.g., one key for terminal-to-network communication, another for terminal-to-application-server communication). This segmentation ensures that compromise of one key does not endanger other communications, resolving the security risk while maintaining operational simplicity through automated key derivation.
Solution Approach 2:
The patent introduces a key derivation function as an intermediary mechanism that transforms the original authentication key material into multiple derived session keys. This intermediary process enables secure key distribution without directly sharing the original sensitive keys, thus maintaining cryptographic security while facilitating ease of operation through systematic key generation.
2Reliability
If existing protocols are modified to enhance security, then cryptographic security is improved, but device complexity and implementation cost increase
Solution Approach 1:
The patent creates a universal key derivation mechanism that works across multiple communication scenarios and protocols. The same derivation function can generate keys for different purposes (IMS signaling, application layer communication, multicast) without requiring separate protocol modifications, thus improving security while avoiding increased device complexity.
Solution Approach 2:
The key derivation function operates autonomously within the existing authentication framework, automatically generating derived session keys from the authentication key material without requiring external intervention or protocol changes. This self-service approach enhances security while maintaining implementation simplicity.
Data Source
AI summary
A first cryptographic key (318) and a second cryptographic key (322) are created by a mobile radio terminal (103) and by a computer of the home communications network (108, 109) by using authentication key materials (312). The first cryptographic key (318) is transmitted to the computer of the visited communications network (113), and the second cryptographic key (322) is transmitted to an application server computer (106, 107).


