Hierarchical Key Hierarchy for Network Slicing Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems face inefficiencies in managing multiple services over a single physical network, as separate authentication and key agreement processes for each service lead to unnecessary signaling and management overhead due to different service requirements.
Innovation Solution
A method and device configuration that generate service-specific network connectivity root keys based on a device-specific root key, allowing each service to operate with distinct security keys without repeating the full authentication and key agreement process, using a Session Key Management Function (SKMF) to derive and manage these keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate authentication and key agreement processes are performed for each service, then individualized security for each service is achieved, but signaling and management overhead increases
Solution Approach 1:
The patent segments the key management system into hierarchical levels: a device-specific root key and service-specific derived keys. This segmentation allows each service to have its own security context while sharing the common device authentication, thereby providing individualized security without requiring separate full authentication processes for each service.
Solution Approach 2:
The device-specific root key is established through a single preliminary authentication and key agreement process before service activation. This preliminary action creates a parent security context that can be reused and derived for multiple services, eliminating the need to repeat the full authentication process for each subsequent service.
2Reliability
If separate authentication and key agreement processes are performed for each service, then individualized security for each service is achieved, but management complexity increases
Solution Approach 1:
The patent divides key management into hierarchical segments where a single device-specific root key manages multiple service-specific keys. This segmentation simplifies management complexity by reducing the number of independent authentication processes while maintaining individualized security through service-specific key derivation.
Solution Approach 2:
The device-specific root key serves as a universal parent key that can derive security contexts for multiple different services. This multi-functionality allows a single authentication process to support numerous services, reducing management complexity while maintaining service-specific security.
3Loss of time
If a single security context is used for multiple services, then signaling overhead is reduced, but network isolation for different services is compromised
Solution Approach 1:
The patent segments the single security context into multiple service-specific security contexts through key derivation. Each service receives a unique derived key while sharing the common device root key, achieving both reduced signaling overhead (compared to separate authentications) and maintained network isolation (through service-specific keys).
Solution Approach 2:
The patent implements a nested key hierarchy where service-specific keys are nested within the device-specific root key. This nesting structure allows service-specific security contexts to be contained within the broader device authentication framework, providing both efficiency and isolation.
Data Source
AI summary
A method is provided for facilitating service-specific security while avoiding a full authentication and key agreement exchange each time a service is activated on a device. Multiple services on a single device and sharing the same session link (e.g., radio link or radio bearer) and the same physical network may nonetheless obtain distinct service-specific network connectivity root keys from which service-specific security/session keys may be derived. In such case, instead of performing a full authentication and key agreement exchange with an operator or provider (e.g., home subscription server or HSS), the device may authenticate a network slice using a security credential established during a prior authentication with another network slice.


