Key Derivation Function for Secure SIP/IMS Signaling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic key exchange mechanisms in secure communication over networks face challenges such as scalability issues, high computational costs, and vulnerabilities to attacks like 'SSRC collision' and 'two-time-pad' in symmetrical cryptography, particularly in environments like SIP/IMS, where they fail to support forking/retargeting, efficient multicast, and early media securely without relying on expensive cryptography or complex signaling traffic.

Innovation Solution

A flexible and lightweight cryptographic key exchange mechanism that allows endpoints to use a secure signaling infrastructure to establish master keys, supporting forking/retargeting, efficient multicast, and early media, by transmitting a value that can be used as a key or for key derivation, with indications specifying its usage, thereby avoiding complex computations and expensive cryptography.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If public key cryptography and PKI are used to establish secure communication, then security and key exchange capability are improved, but computational cost and system complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a key derivation function as an intermediary mechanism that transforms a master key into multiple session keys. This mediator enables secure key exchange without requiring expensive public key cryptography operations, resolving the contradiction between security and computational complexity by providing a lightweight cryptographic approach

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the master key into multiple session keys through the key derivation function. Instead of using a single heavy cryptographic operation, the system divides the key management task into multiple lighter operations, reducing computational burden while maintaining security through proper key derivation

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If symmetrical cryptography with a single master key is used, then ease of operation is improved, but vulnerability to attacks like SSRC collision and two-time-pad increases

Engineering Contradiction:
Improvekey management simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the master key into multiple session keys using a key derivation function. Each session gets its own derived key, preventing SSRC collision and two-time-pad attacks while maintaining the simplicity of symmetrical cryptography. This segmentation allows the system to keep the master key secure while deriving multiple secure session keys

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter from a single master key to multiple derived session keys. By transforming the key parameter through the key derivation function, the system maintains ease of operation with symmetrical cryptography while improving security through proper key parameter management and derivation

Inventive Principle:
Principle #35Parameter changes

3Reliability

If existing key exchange mechanisms are used in SIP/IMS environments, then secure communication is achieved, but support for forking/retargeting, efficient multicast, and early media is insufficient

Engineering Contradiction:
Improvesecure communicationVSAvoidsupport for advanced features
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal key exchange mechanism that handles multiple functions: secure communication, forking/retargeting, efficient multicast, and early media. The key derivation function serves multiple purposes, enabling the system to adapt to different communication scenarios without requiring separate key management mechanisms for each feature

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If expensive cryptographic operations are used to ensure security, then security is improved, but computational overhead and processing time increase

Engineering Contradiction:
ImprovesecurityVSAvoidcomputational overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent uses lightweight symmetric key derivation instead of expensive public key operations. The key derivation function creates secure session keys through efficient cryptographic operations that consume less computational resources, providing security without the high computational overhead associated with public key cryptography

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS8924722B2Apparatus, method, system and program for secure communication
Publication Date: 2014.12.30 HMD GLOBAL
  • US8924722B2 patent drawing
  • US8924722B2 patent drawing
  • US8924722B2 patent drawing

AI summary

Embodiments provide an apparatus, method, product and storage medium for secure communication, wherein a message is sent over a secure signalling path to a recipient, the message including a value indicating a key for encrypting or decrypting information for secure communication, or a key derivation value for deriving a key. The message further includes an indication indicating the type of usage of the value. The receiver of the message may return a message which also includes a key or key derivation value and an indication indicating the type of key or type of usage of the value.