MTC Key Management for Secure Network-to-UE Transmission
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The 3GPP study has not fulfilled the requirement for secure communication between an MTC device and an MTC-IWF, necessitating a solution to ensure secure key management and transmission.
Innovation Solution
The network derives and sends the root key K_iwf to the MTC UE, with options including derivation by the HSS, MME/SGSN/MSC, or MTC-IWF, and transmission through various messages and interfaces to ensure secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the 3GPP study approach is used for security, then standardization process is followed, but secure communication between MTC device and MTC-IWF is not achieved
Solution Approach 1:
The patent performs preliminary key derivation and establishment of security context before actual MTC communication begins. The network derives the root key K_iwf and establishes security parameters in advance through authentication procedures, ensuring secure communication is ready before data transmission starts.
Solution Approach 2:
The patent introduces the MTC-IWF as an intermediary function that mediates between the MTC device and the network. This intermediary derives and manages the root key K_iwf, acting as a security gateway that enables secure communication without requiring the device to directly establish security with multiple network elements.
2Adaptability or versatility
If multiple network nodes derive the root key K_iwf, then flexibility in key management is improved, but key management complexity increases
Solution Approach 1:
The patent segments the key management functionality across different network nodes (HSS, MME, MTC-IWF), allowing each node to independently derive the root key K_iwf based on available authentication data. This segmentation provides flexibility while maintaining clear separation of responsibilities for key derivation, management, and distribution.
Solution Approach 2:
The patent allows different parameters (authentication data, node identifiers, derivation algorithms) to be changed based on which network node performs key derivation. The system adapts the key derivation process by changing input parameters and derivation methods depending on the specific network architecture and available resources at each node.
Data Source
AI summary
A root key (K_iwf) is derived at a network and sent to MTC UE (10). The K_iwf is used for deriving subkeys for protecting communication between MTC UE (10) and MTC-IWF (20). In a case where HSS (30) derives the K_iwf, HSS (30) send to MTC-IWF (20) the K_iwf in a new message (Update Subscriber Information). In a case where MME (40) derives the K_iwf, MME (40) sends the K_iwf through HSS (30) or directly to MTC-IWF (20). MTC-IWF (20) can derive the K_iwf itself. The K_iwf is sent through MME (40) to MTC UE (10) by use of a NAS SMC or Attach Accept message, or sent from MTC-IWF (20) directly to MTC UE (10). In a case where the K_iwf is sent from MME (40), MME (40) receives the K_iwf from HSS (30) in an Authentication Data Response message, or from MTC-IWF (20) directly.


