Key Distribution in Wireless Networks via MME Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing key distribution methods in wireless communication networks, such as UMTS, are inadequate for the evolved 3GPP network, which requires secure key distribution for access stratum, non-access stratum signaling, and user data security, as they can only deduce and distribute a single set of keys to entities performing security operations.
Innovation Solution
A method and system for key distribution in wireless communication networks that involves receiving a root key from a Home Subscriber Server (HSS) by a Mobility Management Entity (MME), deducing keys for access stratum, non-access stratum signaling, and user data security, and sending these keys to entities performing security operations, with the option for user equipment (UE) to also deduce these keys independently or cooperatively with the MME.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a single set of keys is distributed to entities performing security operations (as in UMTS), then the device complexity is reduced, but the adaptability to evolved network requirements (multiple security associations) deteriorates
Solution Approach 1:
The patent segments the single key distribution mechanism into multiple independent key sets (first set for AS signaling, second set for NAS signaling, third set for user data). Each key set is independently managed and distributed to appropriate entities, allowing the system to support multiple security associations simultaneously while maintaining clear separation of concerns and manageable complexity.
2Adaptability or versatility
If multiple sets of keys are distributed for different security associations, then the adaptability to evolved network requirements is improved, but the device complexity increases
Solution Approach 1:
The MME acts as an intermediary entity that receives the master key from HSS, derives multiple separate key sets, and distributes them to appropriate entities (eNB, UE). This intermediary approach centralizes the complex key derivation logic in one location, simplifying key management at other entities while still providing comprehensive security coverage for multiple associations.
Solution Approach 2:
The system changes the parameter structure by introducing multiple distinct key sets with different purposes and distribution targets. Each key set is configured with specific parameters (key purpose, distribution target, security level) that allow flexible adaptation to different security requirements without creating a monolithic complex structure.
3Reliability
If separate keys are distributed for AS signaling, NAS signaling, and user data, then the security level is improved, but the loss of information (key management overhead) increases
Solution Approach 1:
The MME performs preliminary key derivation actions by receiving the master key from HSS and pre-derived all necessary key sets (AS, NAS, user data keys) before actual security operations begin. This preliminary preparation eliminates the need for real-time key derivation during critical security operations, reducing overhead and improving efficiency while maintaining high security standards.
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
A method for distributing keys in a wireless communication network includes: receiving, by a mobility management entity, MME, a root key from a home subscriber server, HSS; deducing, by the MME, the keys for protecting the security of an access stratum, AS, signaling, a non-access stratum, NAS, signaling and user data according to the root key; and sending, by the MME, the keys to entities performing security operation; so that the keys for protecting the security of the AS signaling, the NAS signaling and user data in a wireless communication network are deduced and distributed and the security of network communication is guaranteed.