Key Derivation for MME Relocation in Cellular Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Future cellular network architectures face security challenges as mobility management entities (MMEs) are moved to the network edge, where they are less secure and lack physical isolation, necessitating improved security measures for key management and authentication.
Innovation Solution
A method and device for securely managing keys in cellular networks by deriving digital keys based on data from control plane messages and shared keys with a key management device, ensuring secure communication during service area changes and handovers, using a session key management function (SKMF) to authenticate and derive keys for MMEs, even when they are relocated.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If MMEs are moved to the network edge to improve service coverage and responsiveness, then network performance and accessibility are improved, but security and physical isolation are worsened
Solution Approach 1:
The patent introduces an intermediary key management architecture where the HSS and MME do not directly share authentication vectors. Instead, the MME derives keys locally using a key derivation function with inputs from the HSS and random values, acting as a mediator that eliminates the need for direct trusted connection between HSS and MME. This allows MMEs to be deployed at network edges without compromising security.
Solution Approach 2:
The patent extracts the authentication vector forwarding mechanism from the traditional HSS-MME direct connection model. By removing the need to forward authentication vectors to MMEs and instead enabling local key derivation at the MME, the system eliminates the security vulnerability associated with MMEs being physically accessible at network edges while maintaining authentication functionality.
2Ease of operation
If authentication vectors are forwarded to MMEs to enable authentication, then authentication functionality is ensured, but key security and freshness are worsened due to frequent key refreshing requirements
Solution Approach 1:
The MME performs self-service key derivation by locally computing authentication keys using a key derivation function. Instead of relying on the network to forward updated authentication vectors to refresh keys, the MME autonomously derives fresh keys using random values and inputs from the HSS, eliminating the need for frequent key refreshing and associated security risks.
Solution Approach 2:
The system performs preliminary key derivation setup where the HSS provides necessary inputs (such as subscription information and random values) to the MME in advance. The MME then uses these pre-provided inputs to derive authentication keys locally, eliminating the need for subsequent key refreshing operations and ensuring continuous security without operational interruptions.
3Productivity
If multiple MME instances are hosted on single physical hardware to improve resource utilization, then device efficiency is improved, but security isolation and key management are worsened
Solution Approach 1:
The patent segments the key management functionality by implementing individual key derivation processes for each MME instance, even when multiple instances share the same physical hardware. Each MME maintains separate authentication contexts and derives keys independently using unique random values, ensuring logical security isolation despite physical co-location.
Solution Approach 2:
Each MME instance performs local key derivation with its own unique security context and random values. This local quality approach ensures that even though multiple MMEs share physical hardware, each instance maintains independent security boundaries through localized key generation processes, preventing cross-contamination of authentication credentials.
Data Source
AI summary
A device that identifies entry into a new service area, transmits a service area update request to a network device associated with a network, receives a control plane message from the network indicating control plane device relocation or a key refresh due to a service area change in response to transmitting the service area update request, and derives a first key based in part on data included in the control plane message and a second key shared between the device and a key management device. Another device that receives a handover command from a network device associated with a network, the handover command indicating a new service area, derives a first key based on data included in the handover command and on a second key shared between the device and a key management device, and sends a handover confirmation message that is secured based on the first key.


