Key Derivation for Non-3GPP Access Using Type Distinguishers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The current 5G system's key hierarchy uses the same access network key (K_N3IWF) for different non-3GPP access types, risking impersonation fraud where one access network can masquerade as another, compromising security.
Innovation Solution
Different keys are derived by the core network and UE for each non-3GPP access type using a key derivation function with unique access type distinguisher values, ensuring each key is tied to its specific access type and preventing impersonation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the same access network key (K_N3IWF) is used for different non-3GPP access types, then the key management system is simple and unified, but security is compromised as one access network can impersonate another
Solution Approach 1:
The patent segments the unified access network key into multiple access-type-specific keys (K_N3IWF_Type1, K_N3IWF_Type2, etc.), where each key is dedicated to a specific non-3GPP access type. This segmentation prevents impersonation attacks while maintaining manageable key derivation through type-specific distinguishers.
Solution Approach 2:
The patent applies local quality by making each access network key unique to its specific access type through the incorporation of access type distinguishers (ATD) in the key derivation process. Each key has localized security properties tailored to its specific access type, preventing cross-type impersonation.
2Reliability
If different keys are derived for each non-3GPP access type using unique access type distinguisher values, then security is enhanced by preventing impersonation, but the key management system becomes more complex
Solution Approach 1:
The patent performs preliminary action by pre-defining access type distinguishers for different non-3GPP access types before key derivation. These distinguishers are incorporated into the key derivation function to automatically generate type-specific keys, reducing the need for manual key management while enhancing security.
Solution Approach 2:
The patent changes the parameter space by introducing access type distinguishers as additional input parameters to the key derivation function. This allows the system to derive different keys for different access types using the same base secret, managing complexity through parameterization rather than separate key storage.
3Ease of operation
If a unified key hierarchy is maintained for all non-3GPP access networks, then the system structure is simple and easy to implement, but fraud prevention capability is reduced
Solution Approach 1:
The patent introduces access type distinguishers as intermediaries between the unified key hierarchy and the specific access networks. These distinguishers act as mediators that enable the system to derive type-specific keys from a unified base secret, maintaining structural simplicity while preventing fraud through key differentiation.
Data Source
AI summary
A method for key derivation for non-3GPP access. The method includes determining a particular non-3GPP access type, wherein the particular non-3GPP access type is one of N different particular non-3GPP access types (N>1), and each one of the N particular non-3GPP access types is associated with a unique access type distinguisher value. The method also includes generating (s604) a first access network key using a key derivation function and the unique access type distinguisher value with which the determined particular non-3GPP access type is associated, thereby generating a first access network key for the particular non-3GPP access type.


