Key Derivation for Non-3GPP Access Using Type Distinguishers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The current 5G system's key hierarchy uses the same access network key (K_N3IWF) for different non-3GPP access types, risking impersonation fraud where one access network can masquerade as another, compromising security.

Innovation Solution

Different keys are derived by the core network and UE for each non-3GPP access type using a key derivation function with unique access type distinguisher values, ensuring each key is tied to its specific access type and preventing impersonation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the same access network key (K_N3IWF) is used for different non-3GPP access types, then the key management system is simple and unified, but security is compromised as one access network can impersonate another

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the unified access network key into multiple access-type-specific keys (K_N3IWF_Type1, K_N3IWF_Type2, etc.), where each key is dedicated to a specific non-3GPP access type. This segmentation prevents impersonation attacks while maintaining manageable key derivation through type-specific distinguishers.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by making each access network key unique to its specific access type through the incorporation of access type distinguishers (ATD) in the key derivation process. Each key has localized security properties tailored to its specific access type, preventing cross-type impersonation.

Inventive Principle:
Principle #3Local quality

2Reliability

If different keys are derived for each non-3GPP access type using unique access type distinguisher values, then security is enhanced by preventing impersonation, but the key management system becomes more complex

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary action by pre-defining access type distinguishers for different non-3GPP access types before key derivation. These distinguishers are incorporated into the key derivation function to automatically generate type-specific keys, reducing the need for manual key management while enhancing security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the parameter space by introducing access type distinguishers as additional input parameters to the key derivation function. This allows the system to derive different keys for different access types using the same base secret, managing complexity through parameterization rather than separate key storage.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If a unified key hierarchy is maintained for all non-3GPP access networks, then the system structure is simple and easy to implement, but fraud prevention capability is reduced

Engineering Contradiction:
Improvesystem implementation easeVSAvoidimpersonation fraud
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces access type distinguishers as intermediaries between the unified key hierarchy and the specific access networks. These distinguishers act as mediators that enable the system to derive type-specific keys from a unified base secret, maintaining structural simplicity while preventing fraud through key differentiation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11997479B2Key derivation for non-3GPP access
Publication Date: 2024.05.28 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US11997479B2 patent drawing
  • US11997479B2 patent drawing
  • US11997479B2 patent drawing

AI summary

A method for key derivation for non-3GPP access. The method includes determining a particular non-3GPP access type, wherein the particular non-3GPP access type is one of N different particular non-3GPP access types (N>1), and each one of the N particular non-3GPP access types is associated with a unique access type distinguisher value. The method also includes generating (s604) a first access network key using a key derivation function and the unique access type distinguisher value with which the determined particular non-3GPP access type is associated, thereby generating a first access network key for the particular non-3GPP access type.