Hierarchical Key Hierarchy for Network Slicing Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems face inefficiencies in managing multiple services over a single physical network, as separate authentication and key agreement processes for each service lead to unnecessary signaling and management overhead due to different service requirements.

Innovation Solution

A method and device configuration that generate service-specific network connectivity root keys based on a device-specific root key, allowing each service to operate with distinct security keys without repeating the full authentication and key agreement process, using a Session Key Management Function (SKMF) to derive and manage these keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate authentication and key agreement processes are performed for each service, then individualized security for each service is achieved, but signaling and management overhead increases

Engineering Contradiction:
Improveindividualized securityVSAvoidsignaling overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the key management system into hierarchical levels: a device-specific root key and service-specific derived keys. This segmentation allows each service to have its own security context while sharing the common device authentication, thereby providing individualized security without requiring separate full authentication processes for each service.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The device-specific root key is established through a single preliminary authentication and key agreement process before service activation. This preliminary action creates a parent security context that can be reused and derived for multiple services, eliminating the need to repeat the full authentication process for each subsequent service.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If separate authentication and key agreement processes are performed for each service, then individualized security for each service is achieved, but management complexity increases

Engineering Contradiction:
Improveindividualized securityVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides key management into hierarchical segments where a single device-specific root key manages multiple service-specific keys. This segmentation simplifies management complexity by reducing the number of independent authentication processes while maintaining individualized security through service-specific key derivation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The device-specific root key serves as a universal parent key that can derive security contexts for multiple different services. This multi-functionality allows a single authentication process to support numerous services, reducing management complexity while maintaining service-specific security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Loss of time

If a single security context is used for multiple services, then signaling overhead is reduced, but network isolation for different services is compromised

Engineering Contradiction:
Improvesignaling overheadVSAvoidnetwork isolation
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The patent segments the single security context into multiple service-specific security contexts through key derivation. Each service receives a unique derived key while sharing the common device root key, achieving both reduced signaling overhead (compared to separate authentications) and maintained network isolation (through service-specific keys).

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a nested key hierarchy where service-specific keys are nested within the device-specific root key. This nesting structure allows service-specific security contexts to be contained within the broader device authentication framework, providing both efficiency and isolation.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS10129235B2Key hierarchy for network slicing
Publication Date: 2018.11.13 QUALCOMM INC
  • US10129235B2 patent drawing
  • US10129235B2 patent drawing
  • US10129235B2 patent drawing

AI summary

A method is provided for facilitating service-specific security while avoiding a full authentication and key agreement exchange each time a service is activated on a device. Multiple services on a single device and sharing the same session link (e.g., radio link or radio bearer) and the same physical network may nonetheless obtain distinct service-specific network connectivity root keys from which service-specific security/session keys may be derived. In such case, instead of performing a full authentication and key agreement exchange with an operator or provider (e.g., home subscription server or HSS), the device may authenticate a network slice using a security credential established during a prior authentication with another network slice.