Key Management Center Service Key Encryption for Mobile Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile communications security architectures face vulnerabilities as intermediate nodes can intercept and decrypt communication data, compromising end-to-end encryption, particularly in outdoor scenarios where base stations are susceptible to attacks.
Innovation Solution
A key distribution method involving a key management center that generates and encrypts service keys using NAF keys, which are then sent via Generic Bootstrapping Architecture (GBA) messages to network elements, ensuring secure communication by allowing them to restore the service keys for encryption and integrity protection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If data is encrypted section by section between network elements, then flexibility of security protection is improved, but security against interception and attacks deteriorates
Solution Approach 1:
A key management center is introduced as an intermediary to manage service keys for network elements. The key management center generates, distributes, and revokes service keys centrally, enabling end-to-end encryption keys to be properly managed while maintaining the flexibility of section-by-section encryption architecture.
Solution Approach 2:
The patent changes the encryption parameter from using intermediate node keys to using end-to-end service keys. Network elements use service keys obtained from the key management center for encryption, transforming the security model from hop-by-hop encryption with intermediate node access to end-to-end encryption with restricted key access.
2Ease of operation
If base stations perform PDCP decryption for outdoor communication, then communication flexibility is improved, but vulnerability to wiretapping and plaintext exposure deteriorates
Solution Approach 1:
The patent applies preliminary anti-action by having the user equipment perform integrity protection and encryption using service keys before data transmission. This prevents the base station from being able to decrypt plaintext even if compromised, as the encryption occurs end-to-end between user equipment and the destination, bypassing the base station's decryption capability.
Solution Approach 2:
The patent extracts the decryption capability from the base station by implementing end-to-end encryption where the base station only handles encrypted data. The service keys are managed by the key management center and used by user equipment, removing the base station's ability to access plaintext and eliminating its vulnerability to wiretapping attacks.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
Embodiments of the present invention disclose a key distribution and receiving method, a key management center, a first network element, and a second network element. The method in the embodiments of the present invention includes: obtaining, by a first key management center, NAF key information of the first network element and a NAF key of the first network element, wherein the NAF key information of the first network element is information required to obtain the NAF key of the first network element; obtaining, by the first key management center, a service key, wherein the service key is used for communication data encryption and/or integrity protection when the first network element communicates with the second network element; using, by the first key management center, the NAF key of the first network element to perform encryption and/or integrity protection on the service key, to generate a first security protection parameter; and sending a first generic bootstrapping architecture GBA push message to the first network element. The GBA push message carries the first security protection parameter and the NAF key information of the first network element. By means of the present invention, data interception and attack in a sending process can be avoided.