Local Network Subscriber Authentication Key Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for authenticating subscribers within local networks without online communication with the home network face security issues due to potential vulnerabilities in less secure local environments and synchronization challenges with the Sequence Number (SQN) mechanism, leading to potential de-synchronization and authentication failures.

Innovation Solution

A method that involves storing a subscriber key per subscriber in the home authentication center, deriving local keys specific to each authorized local network, and provisioning the UICC application with these keys and a key derivation function to perform local authentication, ensuring secure and controlled authentication within local E-UTRAN networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a unique key is shared between the home HSS, the UICC application and all the local networks for authentication, then authentication can be performed in any local network, but security is compromised because an attacker with physical access to a local HSS can retrieve the unique key and compromise all other local networks

Engineering Contradiction:
Improveauthentication capability across local networksVSAvoidsecurity of authentication
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the authentication key into multiple separate local keys, each specific to a particular local network. Instead of using one unique key shared across all local networks, each local network receives its own dedicated local key from the home HSS. This segmentation ensures that compromise of one local network's key does not affect other local networks, thereby resolving the security vulnerability while maintaining authentication capability across multiple networks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by provisioning each local network with its own specific local key rather than a universal key. The UICC application is enhanced to store and use multiple local keys, selecting the appropriate key based on the current local network. This localized key assignment improves security by limiting the impact of key compromise to a single local network while preserving authentication functionality across all authorized local networks.

Inventive Principle:
Principle #3Local quality

2Ease of operation

If the same Sequence Number (SQN) mechanism is used in different local networks not connected to synchronize, then authentication can proceed independently in each network, but de-synchronization of the UICC may occur leading to authentication failures

Engineering Contradiction:
Improveindependent authentication in local networksVSAvoidauthentication success rate
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the SQN mechanism by associating a separate SQN counter with each local key in the UICC application. Instead of using a single shared SQN across all local networks, each local network has its own independent SQN counter that increments separately. This segmentation prevents de-synchronization issues because each local network's authentication process operates with its own independent counter, eliminating the synchronization problem while maintaining ease of independent operation.

Inventive Principle:
Principle #1Segmentation

3Reliability

If online communication between the local network and the home network is required for authentication, then centralized control is maintained, but authentication cannot proceed when the macro network is not available

Engineering Contradiction:
Improvecentralized authentication controlVSAvoidauthentication availability in isolated networks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by pre-provisioning the UICC application with multiple local keys and associated authentication parameters before the subscriber enters a local network. The home HSS securely distributes local keys to the UICC in advance, along with corresponding local network identifiers and SQN counters. This preliminary provisioning enables the UICC to perform autonomous authentication in local networks without real-time communication with the home network, ensuring authentication availability when the macro network is unavailable while maintaining centralized control through the key distribution process.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3345417B1Method to authenticate a subscriber in a local network
Publication Date: 2022.12.28 THALES DIS FRANCE SA
  • EP3345417B1 patent drawingFigure 1~2

AI summary

The present invention relates to a method to authenticate a subscriber (IMSli) within a local network (LNj) comprising preliminary step of deriving a subscriber key (SMKi) in local keys (LKi), one local key (LKiLNj) for each local network (LNj) the subscriber (IMSli) is authorized to access, provisioning each local network (LNj) the subscriber (IMSli) is authorized to access with its own local key (LKiLNj). When an authentication is required in a given local network (LNj), an UlCC application derives a local key (LKiLNj) in the UlCC application of the subscriber (IMSli) using the network identifier (LNj), the key derivation function (KDF) and the subscriber key (SMKi) and use the derived local key (LKiLNj) in the algorithm to perform local authentication in the local network (LNj).