Mobility Session Key Derivation for Edge MME Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Future cellular network architectures with mobility management entities (MMEs) at the network edge face security challenges due to reduced physical isolation and potential multi-ownership, necessitating more frequent key refreshes and secure authentication mechanisms.

Innovation Solution

A method and network device for performing authentication and key agreement, generating mobility session keys based on authentication session keys, and transmitting these keys to MMEs, with features including determining key storage, requesting authentication information from a Home Subscriber Server, and using MME identification values and counter values in key derivation to ensure secure key management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If MMEs are deployed at the network edge to improve service delivery, then service responsiveness is improved, but security is worsened due to reduced physical isolation and increased accessibility

Engineering Contradiction:
Improveservice responsivenessVSAvoidsecurity
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent segments the key management function by introducing a separate key derivation mechanism that operates independently at the MME. Instead of relying on a centralized authentication server for all key operations, the MME locally derives mobility management keys from authentication keys, creating a distributed key management architecture that maintains security while enabling edge deployment

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary key derivation process that acts as a security buffer between the authentication credentials and the mobility management functions. The authentication key serves as an intermediary that is transformed into mobility management keys through a secure derivation function, preventing direct exposure of authentication credentials while enabling secure edge-based MME operations

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication keys are refreshed more frequently to improve security, then security is improved, but signaling overhead and processing time increase

Engineering Contradiction:
ImprovesecurityVSAvoidkey refresh time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary key derivation during the initial authentication process, establishing mobility management keys before they are needed for mobility operations. This preliminary action eliminates the need for frequent key refreshes during mobility events, as the derived keys can be reused across multiple mobility procedures within their validity period

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a periodic key usage model where mobility management keys are derived and used for a defined period or number of mobility events. This periodic action reduces the frequency of key refresh operations compared to per-event key generation, thereby reducing signaling overhead and processing time while maintaining security through controlled key lifecycle management

Inventive Principle:
Principle #19Periodic action

3Productivity

If multiple MME instances are hosted within a single physical hardware device to improve resource utilization, then resource efficiency is improved, but security isolation is worsened

Engineering Contradiction:
Improveresource efficiencyVSAvoidsecurity isolation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies local quality by providing each MME instance with its own uniquely derived mobility management keys that are specific to that instance. Even though multiple MMEs share the same physical hardware, each instance has distinct cryptographic credentials derived from the authentication key combined with instance-specific identifiers, ensuring security isolation at the cryptographic level

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the cryptographic parameters by deriving different mobility management keys for different MME instances using instance-specific parameters such as MME identifiers. This parameter differentiation ensures that even though multiple instances share hardware resources, their security contexts are mathematically distinct and isolated, preventing cross-instance security compromises

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3806512B1Apparatuses and methods for wireless communication
Publication Date: 2024.12.04 QUALCOMM INC
  • EP3806512B1 patent drawingFigure 1
  • EP3806512B1 patent drawingFigure 2
  • EP3806512B1 patent drawingFigure 3A

AI summary

Authentication and key agreement is performed with a device and authentication information associated with the device is obtained, the authentication information including t an authentication session key. A session key management entity (SKME) generates a mobility session key based on the authentication session key and transmits the mobility session key to a mobility management entity (MME) serving the device.