MEC Key Identification Using KSI for Service-Specific Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile edge computing (MEC) systems lack a method to distinguish different keys for MEC entities using the same UE identities, leading to security issues due to non-unique keys derived per MEC function.

Innovation Solution

A unique Key Set Identifier (KSI) is generated by the UE, which is used as input to a key derivation function (KDF) to derive specific keys for each MEC service, ensuring unique keys for different MEC functions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If the same UE identities are used for multiple MEC services, then the system simplifies identity management, but it causes inability to distinguish different keys for MEC entities leading to security issues

Engineering Contradiction:
Improveidentity management complexityVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the key management system by introducing a Key Set Identifier (KSI) that divides the previously unified key into service-specific keys. Each MEC service now has its own derived key (KECS, KEES, KEAS) based on the KSI, allowing differentiation while maintaining simplified identity management at the UE level.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by making keys service-specific rather than universal. The KSI enables each MEC service (edge configuration server, edge enabler server, edge application server) to have its own unique key derived from the same root key, providing localized security quality for each service while maintaining overall system simplicity.

Inventive Principle:
Principle #3Local quality

2Reliability

If unique keys are derived for each MEC service using KSI, then security is enhanced, but the key derivation process becomes more complex

Engineering Contradiction:
ImprovesecurityVSAvoidkey derivation process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-defining the key derivation structure and relationships before actual MEC service operations. The KSI is established upfront, and the derivation paths for KECS, KEES, and KEAS are predetermined through the key derivation function, simplifying the actual key generation process during service operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces the Key Set Identifier (KSI) as an intermediary element that mediates between the root key and service-specific keys. The KSI acts as a bridge that enables systematic key derivation while maintaining a clear and manageable process, reducing the apparent complexity by providing a structured intermediate step.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If key derivation function is used with KSI input, then unique keys are ensured for each service, but the computational overhead increases

Engineering Contradiction:
Improvekey uniquenessVSAvoidcomputational energy
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent changes the input parameter of the key derivation function from generic UE identities to the specific Key Set Identifier (KSI). This parameter change enables unique key generation for each service while maintaining computational efficiency, as the KSI provides a compact and structured input that optimizes the derivation process.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12621660B2Key identification for mobile edge computing functions
Publication Date: 2026.05.05 LENOVO (SINGAPORE) PTE LTD
  • US12621660B2 patent drawing
  • US12621660B2 patent drawing
  • US12621660B2 patent drawing

AI summary

Various aspects of the present disclosure relate to key identification for mobile edge computing functions. An apparatus includes at least one memory and at least one processor that is configured to generate a unique key set identifier (“KSI”) associated with a multi-access edge computing (“MEC”) service, derive a key for a network function based on a corresponding root key and the generated KSI, the KSI provided as input to a key derivation function (“KDF”), and transmit an application registration request message to the network function for establishing a secure connection to the network function using the key, the application registration request message comprising the KSI.