Deployable LTE Authentication Key Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

During natural disasters, when connectivity to fixed LTE networks is lost, emergency communication is impacted, and deploying a temporary LTE infrastructure poses risks of compromising authentication keys stored on the fixed LTE network infrastructure.

Innovation Solution

A method where a deployable LTE system derives a unique authentication key from the fixed system, stores it, and uses it to authenticate communication devices without connecting to the fixed system, thereby maintaining security of the authentication keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If authentication keys are replicated from fixed HSS to deployable HSS to enable authentication in emergency situations, then communication coverage is extended to remote locations, but authentication keys become vulnerable to compromise in the less secure mobile environment

Engineering Contradiction:
Improvecommunication coverageVSAvoidauthentication key security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the authentication key into two parts: a static key stored securely in the HSS and a dynamic key component generated locally in the deployable system. This segmentation allows the deployable system to perform authentication without having the complete authentication key, thus maintaining security while enabling emergency communication coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication mechanism where the deployable system generates authentication vectors using a derived key rather than directly using the master authentication key. This intermediary process allows authentication to occur in the deployable environment without exposing the sensitive master key, bridging the gap between security requirements and emergency coverage needs.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If deployable LTE infrastructure is activated independently without connection to fixed LTE network infrastructure, then emergency communication coverage is provided, but the authentication process cannot be completed using standard HSS connectivity

Engineering Contradiction:
Improveemergency communication capabilityVSAvoidauthentication process complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-configuring the deployable system with a derived key that can be used to generate authentication vectors independently. This pre-preparation allows the deployable system to immediately provide emergency communication services without needing to connect to the fixed HSS, while the authentication process remains manageable through the use of pre-computed authentication parameters.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9843928B2Method and apparatus for connecting a communication device to a deployable network without compromising authentication keys
Publication Date: 2017.12.12 MOTOROLA SOLUTIONS INC
  • US9843928B2 patent drawing
  • US9843928B2 patent drawing
  • US9843928B2 patent drawing

AI summary

A method and apparatus is provided for connecting a communication device to a deployable system. The deployable system obtains at least one deployable key derived on a fixed system for the deployable system based on an existing key stored on a database of the fixed system, wherein the existing key is used to authenticate a communication device. The deployable system stores the derived key. Subsequent to the storing, the deployable system is activated to provide communication resources to communication devices disconnected from the fixed system. The activated deployable system is not connected to the fixed system. The activated deployable system receives an authentication request from the communication device requesting connection to the deployable system; generates authentication vectors using the at least one derived deployable key; and authenticates an authentication response received from the communication device using the authentication vectors.