Mobile Security Key Generation via Hierarchical Derivation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional mobile communication systems, such as CDMA 1×EV-DO, face security issues like channel hijacking and service fraud due to inadequate authentication methods, and they struggle with efficient key management, leading to slow security procedures and vulnerabilities in Ultra Mobile Broadband (UMB) networks.

Innovation Solution

A method and apparatus for securely generating and managing security keys in a mobile communication system, involving an AAA server generating Master Session Keys (MSK) and Extended MSK (EMSK), which are then used to create various session and authentication keys, including Device-MSK, User-MSK, and Traffic Session Key (TSK), ensuring robust authentication and encryption across the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication methods (CHAP/PAP) are used in mobile communication systems, then the system can maintain compatibility with existing protocols, but the system becomes vulnerable to channel hijacking and service fraud attacks

Engineering Contradiction:
Improveauthentication securityVSAvoidchannel hijacking and service fraud
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the authentication parameters by introducing a challenge-response mechanism with random challenges and time-stamped authentication vectors. Instead of using static passwords or simple challenge-handshake protocols, the system employs dynamic authentication parameters including random challenges, sequence numbers, and time-based validation to prevent replay attacks and channel hijacking.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an authentication server as an intermediary entity that mediates between the mobile station and the network. This intermediary generates and manages authentication vectors, validates challenge-response pairs, and coordinates the mutual authentication process, thereby providing a secure framework that protects both parties from fraud and hijacking attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple security keys are used for comprehensive security coverage, then the security coverage is improved, but the key management complexity and procedure execution time increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidsecurity procedure execution time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the security key structure into multiple hierarchical levels including master keys, session keys, and derived authentication keys. Each key serves a specific security function (encryption, authentication, integrity protection), allowing comprehensive security coverage while enabling parallel processing of different security operations without sequential bottlenecks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary key generation and distribution through authentication vectors before actual data transmission begins. The authentication server pre-generates authentication vectors containing multiple keys and parameters, which are then used during the connection establishment phase, allowing the actual data communication to proceed without repeated key management overhead.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive authentication and security procedures are implemented, then security against message attacks is improved, but the procedure complexity and execution time increase

Engineering Contradiction:
Improveprotection against message attacksVSAvoidsecurity procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication framework that handles multiple attack scenarios (replay attacks, man-in-the-middle attacks, service fraud) through a single integrated procedure. The challenge-response mechanism with authentication vectors serves multiple security functions simultaneously, eliminating the need for separate specialized procedures for different attack types and reducing overall procedural complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent incorporates feedback mechanisms where the authentication server validates each authentication vector and provides immediate acceptance or rejection responses. The mobile station and network continuously exchange validation results and update their security states based on this feedback, enabling efficient detection and rejection of malicious messages without requiring complex multi-step verification procedures.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8571211B2Method and apparatus for generating security key in a mobile communication system
Publication Date: 2013.10.29 SAMSUNG ELECTRONICS CO LTD
  • US8571211B2 patent drawing
  • US8571211B2 patent drawing
  • US8571211B2 patent drawing

AI summary

Disclosed is an apparatus and method for generating a security key in a mobile communication system that performs security key generation. An Authentication, Authorization and Accounting (AAA) server generates a Master Session Key (MSK) and an Enhanced MSK (EMSK) from a Long Term Credential key, and a Device-MSK (D-MSK), a User-MSK (U-MSK) and a Device and User-MSK (DU-MSK) from the MSK and the EMSK. An Access Gateway (AG) generates a Root-MSK (R-MSK) from the MSK and EMSK received from the AAA server. A Signaling Radio Network Controller (SRNC) generates a Pairwise Master Key (PMK) from the R-MSK received from the AG, and a Traffic Session Key (TSK) from the PMK. A Base Station (BS) sets up a radio connection to a Mobile Station (MS) using the TSK received from the SRNC, and performs radio communication using the set radio connection. The MS generates an MSK and an EMSK, and generates there from a D-MSK, a U-MSK, a DU-MSK, an R-MSK, a PMK, an SRK and a TSK, to perform radio communication with the BS.