Key Identifier for Multi-Network Security Context Establishment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication systems require time-consuming full authentication of user equipment (UE) every time it registers with a new serving network, which is inefficient for establishing and maintaining security contexts with multiple networks.

Innovation Solution

The method involves generating a key identifier based on a first key and a network identifier of a second network, forwarding this identifier to the first network to enable identification of the first key, receiving a key count associated with a second key, and generating the second key to establish a security context between the user device and the second network, thereby bypassing the need for a full authentication process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If full authentication is performed every time UE registers with a new serving network, then security context establishment is reliable, but authentication time and system resources are excessively consumed

Engineering Contradiction:
Improvesecurity context establishmentVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs full authentication in advance when the UE first joins a network, establishing a master key and security context. This preliminary authentication result is then reused when the UE moves to new serving networks, avoiding repeated full authentication processes while maintaining security reliability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a universal security context established through initial authentication that can be reused across multiple different serving networks. The master key and security parameters obtained from one authentication can serve multiple network registration scenarios, making the authentication process multi-functional and eliminating redundant verification

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If full authentication is performed every time UE registers with a new serving network, then authentication security is maintained, but system resources are excessively consumed

Engineering Contradiction:
Improveauthentication securityVSAvoiddevice energy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The UE performs full authentication and establishes security context in advance before moving to new networks. This preliminary security setup eliminates the need for repeated energy-intensive authentication processes, significantly reducing device energy consumption during network mobility

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Instead of performing complete full authentication every time, the patent uses partial authentication mechanisms that leverage the previously established master key. Only minimal verification is needed to confirm network identity, consuming far less device energy while maintaining adequate security

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If key identifier is generated and forwarded to enable key identification across networks, then key management efficiency is improved, but protocol complexity increases

Engineering Contradiction:
Improvekey management efficiencyVSAvoidprotocol complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a key identifier as an intermediary element that bridges the UE and serving networks during key management. This identifier enables efficient key recognition and retrieval without requiring complex key exchange protocols, simplifying the overall key management process while improving efficiency

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12052358B2Method and apparatus for multiple registrations
Publication Date: 2024.07.30 QUALCOMM INC
  • US12052358B2 patent drawing
  • US12052358B2 patent drawing
  • US12052358B2 patent drawing

AI summary

A user device having a security context with a first network based on a first key may establish a security context with a second network. In a method, the user device may generate a key identifier based on the first key and a network identifier of the second network. The user device may forward the key identifier to the second network for forwarding to the first network by the second network to enable the first network to identify the first key at the first network. The user device may receive a key count from the second network. The key count may be associated with a second key forwarded to the second network from the first network. The user device may generate the second key based on the first key and the received key count thereby establishing a security context between the second network and the user device.