Local Access Key Derivation for Cellular Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In communication networks, especially hybrid networks like LTE-LAN and LAE, there is a need for a lightweight security solution to protect local radio access between User Equipment (UE) and Access Points (APs) without degrading the security level, while avoiding the high cost and complexity associated with existing security mechanisms that often involve the Core Network (CN).
Innovation Solution
A key derivation mechanism is introduced that generates new Access Stratum (AS) keys in the Radio Access Network (RAN) side without consuming Authentication Vectors (AVs), using a predefined key derivation algorithm based on input parameters such as identifiers and indices, allowing for secure local connections without direct CN involvement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing security mechanisms are used to protect local radio access, then security level is maintained, but cost and complexity increase due to Core Network involvement
Solution Approach 1:
The patent segments the security procedure into two parts: authentication (performed once with CN involvement to generate AV) and key derivation (performed locally in RAN without CN involvement). This segmentation allows the system to maintain high security levels while reducing the complexity and cost of repeated authentication procedures for local access.
Solution Approach 2:
The patent applies preliminary action by performing authentication and generating authentication vectors in advance before local access is needed. The derived keys are then available for immediate use in RAN, eliminating the need for real-time CN involvement during local access operations and reducing procedural complexity.
2Reliability
If Core Network is involved in security procedures, then security level is maintained, but procedure cost increases
Solution Approach 1:
The patent segments the security architecture into CN-based authentication (for initial security establishment) and RAN-based key derivation (for local access). This segmentation reduces CN involvement to only the essential authentication phase, lowering the cost and energy consumption of security procedures while maintaining security levels.
Solution Approach 2:
The patent enables the RAN to perform key derivation autonomously using locally available authentication vectors, without requiring continuous CN involvement. This self-service capability reduces the cost and resource consumption associated with CN participation in every security operation.
3Reliability
If authentication vectors are consumed for key generation, then security keys can be derived, but authentication vectors are depleted
Solution Approach 1:
The patent performs preliminary key derivation during the authentication phase, generating multiple future keys in advance from the authentication vector before it is consumed. This allows the system to have multiple keys available without consuming multiple authentication vectors, preserving AV availability.
Solution Approach 2:
The patent derives more keys than immediately needed from each authentication vector, performing excessive key derivation in advance. This ensures that sufficient keys are available for multiple local access operations without requiring proportional consumption of authentication vectors, maintaining AV availability for future use.
Data Source
AI summary
A method for key derivation may comprise: generating a second key based at least in part on a first key for a first connection between a user equipment and a first network node, in response to a decision to enter an idle mode; releasing the first connection to enter the idle mode; providing an identity of the user equipment to the first network node via a second network node, in response to initiating a setup procedure for a second connection between the user equipment and a second network node; and using the second key for the second connection, in response to receiving from the second network node an indication that the identity of the user equipment is successfully verified at the first network node.


