M2M Cellular Security via Home PLMN Ciphering Key Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cellular networks lack sufficient security, particularly between the Serving GPRS Support Node (SGSN) and Gateway GPRS Support Node (GGSN), which is problematic for Machine-to-Machine (M2M) devices when roaming, leading to potential data interception and increased energy consumption due to high signalling overhead from end-to-end security protocols.
Innovation Solution
A method that generates or stores a Ciphering Key (CK) in the Home PLMN, which is used for encrypted communication between the mobile terminal and a server, rather than the SGSN, and uses cryptographic integrity checks instead of CRC for data link layer messages, reducing signalling overhead and enhancing security without extending user plane encryption to the GGSN/Packet Data Network (PDN) gateway.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If end-to-end security protocols (e.g., DTLS) are implemented between MS and application server, then security is improved, but signalling overhead increases and energy consumption increases
Solution Approach 1:
The patent extracts the security function from the application layer and relocates it to the network layer by implementing encryption between MS and SGSN. This eliminates the need for separate end-to-end security protocols at the application layer, thereby removing the associated signalling overhead and energy consumption while maintaining security.
Solution Approach 2:
The patent performs security setup in advance by establishing encryption keys and parameters during initial attachment or TAU procedures. This preliminary action ensures that security is already in place before data transmission begins, eliminating the need for runtime security handshakes and reducing energy consumption during actual data transfers.
2Reliability
If end-to-end security protocols are implemented, then security is improved, but radio access capacity is reduced
Solution Approach 1:
By extracting the security function to the network layer, the patent removes the need for application-layer security protocols that generate excessive signalling traffic. This reduces the proportion of radio resources dedicated to security signalling, thereby increasing available capacity for actual data transmission.
3Reliability
If user plane encryption is extended to GGSN/PDN gateway, then security is improved, but device complexity and network complexity increase
Solution Approach 1:
The patent applies encryption selectively at the MS-SGSN link rather than extending it throughout the entire user plane to GGSN. This localized approach provides adequate security for M2M communications while avoiding the complexity of implementing and managing encryption across multiple network interfaces and nodes.
4Device complexity
If integrity protection is not supported between MS and SGSN, then device complexity is reduced, but security is weakened
Solution Approach 1:
The patent combines encryption and integrity protection into a unified security framework at the network layer. By merging these functions and implementing them together during initial security setup, the patent provides comprehensive security without significantly increasing device complexity, as both functions are managed through the same security context and keys.
Data Source
Figure 1
Figure 2
AI summary
Facilitating authentication on communication between a mobile terminal and a server is achieved. The communication is made through a Serving GPRS Support Node (SGSN) of a network in which the mobile terminal is operating. A Home Public Land Mobile Network (PLMN) of the mobile terminal generates a ciphering key for encryption of packet-switched data between the mobile terminal and the server. As part of a message from a network entity in the Home PLMN to the SGSN in which the SGSN expects to receive the ciphering key, alternative data is communicated in place of the ciphering key. Secure communication between the mobile terminal and the server is performed by applying encryption using a ciphering key generated by a network entity in a Home PLMN of the mobile terminal in messages between the mobile terminal and the server.