Key Hierarchy for 5G Trusted Network Seamless Handover

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication systems, particularly in 5G networks, face inefficiencies in securing communications between user equipment (UE) and access points (APs) within trusted networks, leading to power consumption, processing resource wastage, and increased network overhead when UE moves between APs, resulting in higher latency and interference.

Innovation Solution

Establishing a key hierarchy based on a main key derived from a 5G core network registration procedure, using IEEE 802.11 protocols to enable seamless communication between APs within the same mobility domain without repeated authentication, thereby conserving power and reducing network overhead.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If repeated authentication procedures are performed when UE moves between APs, then security is maintained, but power consumption and processing resources increase

Engineering Contradiction:
ImprovesecurityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies preliminary action by pre-establishing a key hierarchy structure before the UE moves between APs. The root key is derived during initial network registration, and child keys are pre-computed for multiple APs. This allows the UE to immediately use pre-derived keys when moving between APs without performing authentication from scratch, thus reducing power consumption while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the authentication key into a hierarchical structure with a root key and multiple child keys. Each AP has its own child key derived from the root key. This segmentation allows the system to maintain security at the root level while enabling efficient, low-power operation at individual AP levels by using only the necessary child key for current location.

Inventive Principle:
Principle #1Segmentation

2Reliability

If repeated authentication procedures are performed when UE moves between APs, then security is maintained, but processing resources are wasted

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing resources
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by pre-establishing a key hierarchy structure before the UE moves between APs. The root key is derived during initial network registration, and child keys are pre-computed for multiple APs. This allows the UE to immediately use pre-derived keys when moving between APs without performing authentication from scratch, thus reducing power consumption while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the authentication key into a hierarchical structure with a root key and multiple child keys. Each AP has its own child key derived from the root key. This segmentation allows the system to maintain security at the root level while enabling efficient, low-power operation at individual AP levels by using only the necessary child key for current location.

Inventive Principle:
Principle #1Segmentation

3Reliability

If repeated authentication procedures are performed when UE moves between APs, then security is maintained, but network overhead increases

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-establishing a key hierarchy structure before the UE moves between APs. The root key is derived during initial network registration, and child keys are pre-computed for multiple APs. This allows the UE to immediately use pre-derived keys when moving between APs without performing authentication from scratch, thus reducing power consumption while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the authentication key into a hierarchical structure with a root key and multiple child keys. Each AP has its own child key derived from the root key. This segmentation allows the system to maintain security at the root level while enabling efficient, low-power operation at individual AP levels by using only the necessary child key for current location.

Inventive Principle:
Principle #1Segmentation

4Reliability

If repeated authentication procedures are performed when UE moves between APs, then security is maintained, but latency increases

Engineering Contradiction:
ImprovesecurityVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-establishing a key hierarchy structure before the UE moves between APs. The root key is derived during initial network registration, and child keys are pre-computed for multiple APs. This allows the UE to immediately use pre-derived keys when moving between APs without performing authentication from scratch, thus reducing power consumption while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the authentication key into a hierarchical structure with a root key and multiple child keys. Each AP has its own child key derived from the root key. This segmentation allows the system to maintain security at the root level while enabling efficient, low-power operation at individual AP levels by using only the necessary child key for current location.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20240155338A1Key hierarchies in trusted networks with 5g networks
Publication Date: 2024.05.09 QUALCOMM INC
  • US20240155338A1 patent drawing
  • US20240155338A1 patent drawing
  • US20240155338A1 patent drawing

AI summary

Various aspects of the present disclosure generally relate to wireless communication. In some aspects, a user equipment (UE) may perform a registration procedure with a mobility function of a 5G core network. Accordingly, the UE may derive a main key, associated with a trusted network gateway function, based on the registration procedure. The UE may further determine a root key based on the main key. The UE may derive a first pairwise master key (PMK), associated with a trusted network, from the root key. The UE may communicate with a first access point (AP) for the trusted network. The UE may further derive a second PMK, associated with the second AP, from the first PMK. Numerous other aspects are described.