Local Network Subscriber Authentication Key Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for authenticating subscribers within local networks without online communication with the home network face security issues due to potential vulnerabilities in less secure local environments and synchronization challenges with the Sequence Number (SQN) mechanism, leading to potential de-synchronization and authentication failures.
Innovation Solution
A method that involves storing a subscriber key per subscriber in the home authentication center, deriving local keys specific to each authorized local network, and provisioning the UICC application with these keys and a key derivation function to perform local authentication, ensuring secure and controlled authentication within local E-UTRAN networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a unique key is shared between the home HSS, the UICC application and all the local networks for authentication, then authentication can be performed in any local network, but security is compromised because an attacker with physical access to a local HSS can retrieve the unique key and compromise all other local networks
Solution Approach 1:
The patent segments the authentication key into multiple separate local keys, each specific to a particular local network. Instead of using one unique key shared across all local networks, each local network receives its own dedicated local key from the home HSS. This segmentation ensures that compromise of one local network's key does not affect other local networks, thereby resolving the security vulnerability while maintaining authentication capability across multiple networks.
Solution Approach 2:
The patent implements local quality by provisioning each local network with its own specific local key rather than a universal key. The UICC application is enhanced to store and use multiple local keys, selecting the appropriate key based on the current local network. This localized key assignment improves security by limiting the impact of key compromise to a single local network while preserving authentication functionality across all authorized local networks.
2Ease of operation
If the same Sequence Number (SQN) mechanism is used in different local networks not connected to synchronize, then authentication can proceed independently in each network, but de-synchronization of the UICC may occur leading to authentication failures
Solution Approach 1:
The patent segments the SQN mechanism by associating a separate SQN counter with each local key in the UICC application. Instead of using a single shared SQN across all local networks, each local network has its own independent SQN counter that increments separately. This segmentation prevents de-synchronization issues because each local network's authentication process operates with its own independent counter, eliminating the synchronization problem while maintaining ease of independent operation.
3Reliability
If online communication between the local network and the home network is required for authentication, then centralized control is maintained, but authentication cannot proceed when the macro network is not available
Solution Approach 1:
The patent applies preliminary action by pre-provisioning the UICC application with multiple local keys and associated authentication parameters before the subscriber enters a local network. The home HSS securely distributes local keys to the UICC in advance, along with corresponding local network identifiers and SQN counters. This preliminary provisioning enables the UICC to perform autonomous authentication in local networks without real-time communication with the home network, ensuring authentication availability when the macro network is unavailable while maintaining centralized control through the key distribution process.
Data Source
Figure 1~2
AI summary
The present invention relates to a method to authenticate a subscriber (IMSli) within a local network (LNj) comprising preliminary step of deriving a subscriber key (SMKi) in local keys (LKi), one local key (LKiLNj) for each local network (LNj) the subscriber (IMSli) is authorized to access, provisioning each local network (LNj) the subscriber (IMSli) is authorized to access with its own local key (LKiLNj). When an authentication is required in a given local network (LNj), an UlCC application derives a local key (LKiLNj) in the UlCC application of the subscriber (IMSli) using the network identifier (LNj), the key derivation function (KDF) and the subscriber key (SMKi) and use the derived local key (LKiLNj) in the algorithm to perform local authentication in the local network (LNj).