MEC Key Identification Using KSI for Service-Specific Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile edge computing (MEC) systems lack a method to distinguish different keys for MEC entities using the same UE identities, leading to security issues due to non-unique keys derived per MEC function.
Innovation Solution
A unique Key Set Identifier (KSI) is generated by the UE, which is used as input to a key derivation function (KDF) to derive specific keys for each MEC service, ensuring unique keys for different MEC functions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If the same UE identities are used for multiple MEC services, then the system simplifies identity management, but it causes inability to distinguish different keys for MEC entities leading to security issues
Solution Approach 1:
The patent segments the key management system by introducing a Key Set Identifier (KSI) that divides the previously unified key into service-specific keys. Each MEC service now has its own derived key (KECS, KEES, KEAS) based on the KSI, allowing differentiation while maintaining simplified identity management at the UE level.
Solution Approach 2:
The patent applies local quality by making keys service-specific rather than universal. The KSI enables each MEC service (edge configuration server, edge enabler server, edge application server) to have its own unique key derived from the same root key, providing localized security quality for each service while maintaining overall system simplicity.
2Reliability
If unique keys are derived for each MEC service using KSI, then security is enhanced, but the key derivation process becomes more complex
Solution Approach 1:
The patent applies preliminary action by pre-defining the key derivation structure and relationships before actual MEC service operations. The KSI is established upfront, and the derivation paths for KECS, KEES, and KEAS are predetermined through the key derivation function, simplifying the actual key generation process during service operation.
Solution Approach 2:
The patent introduces the Key Set Identifier (KSI) as an intermediary element that mediates between the root key and service-specific keys. The KSI acts as a bridge that enables systematic key derivation while maintaining a clear and manageable process, reducing the apparent complexity by providing a structured intermediate step.
3Reliability
If key derivation function is used with KSI input, then unique keys are ensured for each service, but the computational overhead increases
Solution Approach 1:
The patent changes the input parameter of the key derivation function from generic UE identities to the specific Key Set Identifier (KSI). This parameter change enables unique key generation for each service while maintaining computational efficiency, as the KSI provides a compact and structured input that optimizes the derivation process.
Data Source
AI summary
Various aspects of the present disclosure relate to key identification for mobile edge computing functions. An apparatus includes at least one memory and at least one processor that is configured to generate a unique key set identifier (“KSI”) associated with a multi-access edge computing (“MEC”) service, derive a key for a network function based on a corresponding root key and the generated KSI, the KSI provided as input to a key derivation function (“KDF”), and transmit an application registration request message to the network function for establishing a secure connection to the network function using the key, the application registration request message comprising the KSI.


