Local Access Key Derivation for Cellular Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In communication networks, especially hybrid networks like LTE-LAN and LAE, there is a need for a lightweight security solution to protect local radio access between User Equipment (UE) and Access Points (APs) without degrading the security level, while avoiding the high cost and complexity associated with existing security mechanisms that often involve the Core Network (CN).

Innovation Solution

A key derivation mechanism is introduced that generates new Access Stratum (AS) keys in the Radio Access Network (RAN) side without consuming Authentication Vectors (AVs), using a predefined key derivation algorithm based on input parameters such as identifiers and indices, allowing for secure local connections without direct CN involvement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing security mechanisms are used to protect local radio access, then security level is maintained, but cost and complexity increase due to Core Network involvement

Engineering Contradiction:
Improvesecurity levelVSAvoidsecurity procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security procedure into two parts: authentication (performed once with CN involvement to generate AV) and key derivation (performed locally in RAN without CN involvement). This segmentation allows the system to maintain high security levels while reducing the complexity and cost of repeated authentication procedures for local access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies preliminary action by performing authentication and generating authentication vectors in advance before local access is needed. The derived keys are then available for immediate use in RAN, eliminating the need for real-time CN involvement during local access operations and reducing procedural complexity.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If Core Network is involved in security procedures, then security level is maintained, but procedure cost increases

Engineering Contradiction:
Improvesecurity levelVSAvoidprocedure cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent segments the security architecture into CN-based authentication (for initial security establishment) and RAN-based key derivation (for local access). This segmentation reduces CN involvement to only the essential authentication phase, lowering the cost and energy consumption of security procedures while maintaining security levels.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent enables the RAN to perform key derivation autonomously using locally available authentication vectors, without requiring continuous CN involvement. This self-service capability reduces the cost and resource consumption associated with CN participation in every security operation.

Inventive Principle:
Principle #25Self-service

3Reliability

If authentication vectors are consumed for key generation, then security keys can be derived, but authentication vectors are depleted

Engineering Contradiction:
Improvesecurity key derivationVSAvoidauthentication vector availability
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent performs preliminary key derivation during the authentication phase, generating multiple future keys in advance from the authentication vector before it is consumed. This allows the system to have multiple keys available without consuming multiple authentication vectors, preserving AV availability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent derives more keys than immediately needed from each authentication vector, performing excessive key derivation in advance. This ensures that sufficient keys are available for multiple local access operations without requiring proportional consumption of authentication vectors, maintaining AV availability for future use.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9942210B2Key derivation method and apparatus for local access under control of a cellular network
Publication Date: 2018.04.10 NOKIA TECHNOLOGIES OY
  • US9942210B2 patent drawing
  • US9942210B2 patent drawing
  • US9942210B2 patent drawing

AI summary

A method for key derivation may comprise: generating a second key based at least in part on a first key for a first connection between a user equipment and a first network node, in response to a decision to enter an idle mode; releasing the first connection to enter the idle mode; providing an identity of the user equipment to the first network node via a second network node, in response to initiating a setup procedure for a second connection between the user equipment and a second network node; and using the second key for the second connection, in response to receiving from the second network node an indication that the identity of the user equipment is successfully verified at the first network node.