Mobile Security Key Generation via Hierarchical Derivation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional mobile communication systems, such as CDMA 1×EV-DO, face security issues like channel hijacking and service fraud due to inadequate authentication methods, and they struggle with efficient key management, leading to slow security procedures and vulnerabilities in Ultra Mobile Broadband (UMB) networks.
Innovation Solution
A method and apparatus for securely generating and managing security keys in a mobile communication system, involving an AAA server generating Master Session Keys (MSK) and Extended MSK (EMSK), which are then used to create various session and authentication keys, including Device-MSK, User-MSK, and Traffic Session Key (TSK), ensuring robust authentication and encryption across the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional authentication methods (CHAP/PAP) are used in mobile communication systems, then the system can maintain compatibility with existing protocols, but the system becomes vulnerable to channel hijacking and service fraud attacks
Solution Approach 1:
The patent changes the authentication parameters by introducing a challenge-response mechanism with random challenges and time-stamped authentication vectors. Instead of using static passwords or simple challenge-handshake protocols, the system employs dynamic authentication parameters including random challenges, sequence numbers, and time-based validation to prevent replay attacks and channel hijacking.
Solution Approach 2:
The patent introduces an authentication server as an intermediary entity that mediates between the mobile station and the network. This intermediary generates and manages authentication vectors, validates challenge-response pairs, and coordinates the mutual authentication process, thereby providing a secure framework that protects both parties from fraud and hijacking attacks.
2Reliability
If multiple security keys are used for comprehensive security coverage, then the security coverage is improved, but the key management complexity and procedure execution time increase
Solution Approach 1:
The patent segments the security key structure into multiple hierarchical levels including master keys, session keys, and derived authentication keys. Each key serves a specific security function (encryption, authentication, integrity protection), allowing comprehensive security coverage while enabling parallel processing of different security operations without sequential bottlenecks.
Solution Approach 2:
The patent performs preliminary key generation and distribution through authentication vectors before actual data transmission begins. The authentication server pre-generates authentication vectors containing multiple keys and parameters, which are then used during the connection establishment phase, allowing the actual data communication to proceed without repeated key management overhead.
3Reliability
If comprehensive authentication and security procedures are implemented, then security against message attacks is improved, but the procedure complexity and execution time increase
Solution Approach 1:
The patent implements a universal authentication framework that handles multiple attack scenarios (replay attacks, man-in-the-middle attacks, service fraud) through a single integrated procedure. The challenge-response mechanism with authentication vectors serves multiple security functions simultaneously, eliminating the need for separate specialized procedures for different attack types and reducing overall procedural complexity.
Solution Approach 2:
The patent incorporates feedback mechanisms where the authentication server validates each authentication vector and provides immediate acceptance or rejection responses. The mobile station and network continuously exchange validation results and update their security states based on this feedback, enabling efficient detection and rejection of malicious messages without requiring complex multi-step verification procedures.
Data Source
AI summary
Disclosed is an apparatus and method for generating a security key in a mobile communication system that performs security key generation. An Authentication, Authorization and Accounting (AAA) server generates a Master Session Key (MSK) and an Enhanced MSK (EMSK) from a Long Term Credential key, and a Device-MSK (D-MSK), a User-MSK (U-MSK) and a Device and User-MSK (DU-MSK) from the MSK and the EMSK. An Access Gateway (AG) generates a Root-MSK (R-MSK) from the MSK and EMSK received from the AAA server. A Signaling Radio Network Controller (SRNC) generates a Pairwise Master Key (PMK) from the R-MSK received from the AG, and a Traffic Session Key (TSK) from the PMK. A Base Station (BS) sets up a radio connection to a Mobile Station (MS) using the TSK received from the SRNC, and performs radio communication using the set radio connection. The MS generates an MSK and an EMSK, and generates there from a D-MSK, a U-MSK, a DU-MSK, an R-MSK, a PMK, an SRK and a TSK, to perform radio communication with the BS.


