Key Distribution in Wireless Networks via MME Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing key distribution methods in wireless communication networks, such as UMTS, are inadequate for the evolved 3GPP network, which requires secure key distribution for access stratum, non-access stratum signaling, and user data security, as they can only deduce and distribute a single set of keys to entities performing security operations.

Innovation Solution

A method and system for key distribution in wireless communication networks that involves receiving a root key from a Home Subscriber Server (HSS) by a Mobility Management Entity (MME), deducing keys for access stratum, non-access stratum signaling, and user data security, and sending these keys to entities performing security operations, with the option for user equipment (UE) to also deduce these keys independently or cooperatively with the MME.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single set of keys is distributed to entities performing security operations (as in UMTS), then the device complexity is reduced, but the adaptability to evolved network requirements (multiple security associations) deteriorates

Engineering Contradiction:
Improvekey distribution complexityVSAvoidadaptability to multiple security associations
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent segments the single key distribution mechanism into multiple independent key sets (first set for AS signaling, second set for NAS signaling, third set for user data). Each key set is independently managed and distributed to appropriate entities, allowing the system to support multiple security associations simultaneously while maintaining clear separation of concerns and manageable complexity.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If multiple sets of keys are distributed for different security associations, then the adaptability to evolved network requirements is improved, but the device complexity increases

Engineering Contradiction:
Improvesupport for multiple security associationsVSAvoidkey management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The MME acts as an intermediary entity that receives the master key from HSS, derives multiple separate key sets, and distributes them to appropriate entities (eNB, UE). This intermediary approach centralizes the complex key derivation logic in one location, simplifying key management at other entities while still providing comprehensive security coverage for multiple associations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the parameter structure by introducing multiple distinct key sets with different purposes and distribution targets. Each key set is configured with specific parameters (key purpose, distribution target, security level) that allow flexible adaptation to different security requirements without creating a monolithic complex structure.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If separate keys are distributed for AS signaling, NAS signaling, and user data, then the security level is improved, but the loss of information (key management overhead) increases

Engineering Contradiction:
Improvesecurity levelVSAvoidkey management overhead
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The MME performs preliminary key derivation actions by receiving the master key from HSS and pre-derived all necessary key sets (AS, NAS, user data keys) before actual security operations begin. This preliminary preparation eliminates the need for real-time key derivation during critical security operations, reducing overhead and improving efficiency while maintaining high security standards.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3700127B1Method and system for key distribution in a wireless communication network
Publication Date: 2024.03.27 BEIJING JINGSHI INTPROP MANAGEMENT CO LTD
  • EP3700127B1 patent drawingFigure 1
  • EP3700127B1 patent drawingFigure 2
  • EP3700127B1 patent drawingFigure 3~4

AI summary

A method for distributing keys in a wireless communication network includes: receiving, by a mobility management entity, MME, a root key from a home subscriber server, HSS; deducing, by the MME, the keys for protecting the security of an access stratum, AS, signaling, a non-access stratum, NAS, signaling and user data according to the root key; and sending, by the MME, the keys to entities performing security operation; so that the keys for protecting the security of the AS signaling, the NAS signaling and user data in a wireless communication network are deduced and distributed and the security of network communication is guaranteed.