Key Generation Method for Mobile Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In existing mobile communications security architectures, the theft or leakage of a permanent key can lead to data leakage, as insiders within network functions can derive and decrypt encrypted data, compromising user plane data transmission security.

Innovation Solution

A key generation method where a terminal device and a user plane network function exchange key update information to derive new protection keys from a permanent key, ensuring that insiders without permission cannot obtain or decrypt the new keys, even if the permanent key is stolen.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the protection key is derived from a permanent key by a core network function, then the security protection operation can be performed, but the insider of the network function can obtain the key and derive the protection key, causing data leakage

Engineering Contradiction:
Improvesecurity protectionVSAvoiddata leakage risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the key derivation process into multiple independent stages involving different network functions (AMF, SEAF, SMF, UPF) and the terminal device. Each entity holds only a portion of the key material or performs only a part of the derivation process, so that no single insider can obtain the complete protection key. The protection key is split into multiple components distributed across different entities, preventing any one party from deriving the full key independently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediate key derivation steps where the terminal device and network functions act as intermediaries in the key generation process. Instead of a core network function directly deriving the protection key from the permanent key, the derivation passes through multiple intermediate stages (KAUSF → KSEAF → KAMF → KgNB) involving different entities, each adding a layer of security and preventing direct access to the final protection key by any single insider.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If the protection key is stolen or leaked, then the encrypted data can be decrypted, but with the new key generation method, the stolen permanent key cannot be used to derive the new protection key

Engineering Contradiction:
Improvedata securityVSAvoidkey generation process
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements dynamic key generation where the protection key is continuously updated and regenerated based on current key material held by the terminal device and network functions. Even if an attacker obtains an old permanent key or protection key, it becomes useless for decrypting current or future communications because the key material is dynamically updated through multiple derivation stages involving fresh inputs from different entities.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent adds temporal and organizational dimensions to key security. Instead of relying on a single static permanent key, the system creates a multi-dimensional key structure where different key components exist at different stages (KAUSF, KSEAF, KAMF, KgNB) and are held by different entities over time. This dimensional expansion ensures that compromising one key or one entity does not expose the entire security structure.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11863977B2Key generation method, device, and system
Publication Date: 2024.01.02 HUAWEI TECH CO LTD
  • US11863977B2 patent drawing
  • US11863977B2 patent drawing
  • US11863977B2 patent drawing

AI summary

A key generation method includes a user plane network function and a terminal device obtain key update information sent by each other. The user plane network function updates, by using the obtained key update information, a sub-key derived from a permanent key, to obtain a new protection key. The terminal device updates, by using the obtained key update information, a sub-key derived from the permanent key, to obtain a new protection key. The terminal device and the user plane network function perform, by using the new protection key, security protection on user plane data transmitted between the terminal device and the user plane network function.