Mobility Session Key Derivation for Edge MME Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Future cellular network architectures with mobility management entities (MMEs) at the network edge face security challenges due to reduced physical isolation and potential multi-ownership, necessitating more frequent key refreshes and secure authentication mechanisms.
Innovation Solution
A method and network device for performing authentication and key agreement, generating mobility session keys based on authentication session keys, and transmitting these keys to MMEs, with features including determining key storage, requesting authentication information from a Home Subscriber Server, and using MME identification values and counter values in key derivation to ensure secure key management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If MMEs are deployed at the network edge to improve service delivery, then service responsiveness is improved, but security is worsened due to reduced physical isolation and increased accessibility
Solution Approach 1:
The patent segments the key management function by introducing a separate key derivation mechanism that operates independently at the MME. Instead of relying on a centralized authentication server for all key operations, the MME locally derives mobility management keys from authentication keys, creating a distributed key management architecture that maintains security while enabling edge deployment
Solution Approach 2:
The patent introduces an intermediary key derivation process that acts as a security buffer between the authentication credentials and the mobility management functions. The authentication key serves as an intermediary that is transformed into mobility management keys through a secure derivation function, preventing direct exposure of authentication credentials while enabling secure edge-based MME operations
2Reliability
If authentication keys are refreshed more frequently to improve security, then security is improved, but signaling overhead and processing time increase
Solution Approach 1:
The patent performs preliminary key derivation during the initial authentication process, establishing mobility management keys before they are needed for mobility operations. This preliminary action eliminates the need for frequent key refreshes during mobility events, as the derived keys can be reused across multiple mobility procedures within their validity period
Solution Approach 2:
The patent implements a periodic key usage model where mobility management keys are derived and used for a defined period or number of mobility events. This periodic action reduces the frequency of key refresh operations compared to per-event key generation, thereby reducing signaling overhead and processing time while maintaining security through controlled key lifecycle management
3Productivity
If multiple MME instances are hosted within a single physical hardware device to improve resource utilization, then resource efficiency is improved, but security isolation is worsened
Solution Approach 1:
The patent applies local quality by providing each MME instance with its own uniquely derived mobility management keys that are specific to that instance. Even though multiple MMEs share the same physical hardware, each instance has distinct cryptographic credentials derived from the authentication key combined with instance-specific identifiers, ensuring security isolation at the cryptographic level
Solution Approach 2:
The patent changes the cryptographic parameters by deriving different mobility management keys for different MME instances using instance-specific parameters such as MME identifiers. This parameter differentiation ensures that even though multiple instances share hardware resources, their security contexts are mathematically distinct and isolated, preventing cross-instance security compromises
Data Source
Figure 1
Figure 2
Figure 3A
AI summary
Authentication and key agreement is performed with a device and authentication information associated with the device is obtained, the authentication information including t an authentication session key. A session key management entity (SKME) generates a mobility session key based on the authentication session key and transmits the mobility session key to a mobility management entity (MME) serving the device.