NAS Key Derivation Using Wireless Channel Data for Forward Secrecy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Legacy approaches for generating non-access stratum (NAS) keys in wireless networks are insecure when the universal subscriber identity module (USIM) is compromised, leading to vulnerabilities in key security.

Innovation Solution

Implementing perfect forward secrecy (PFS) by deriving NAS keys using both symmetric keys and physical layer channel information, ensuring secure key generation even if the USIM is compromised.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If NAS keys are generated using only symmetric keys from USIM, then the key generation process is simple, but the security is compromised when USIM is compromised

Engineering Contradiction:
Improvekey securityVSAvoidkey generation process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines symmetric keys from USIM with physical layer channel information to generate NAS keys. This merging of two different key sources creates a more secure key generation process where compromise of one source (USIM) does not lead to complete key compromise, thus resolving the security vulnerability while maintaining reasonable process complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a composite key structure by deriving NAS keys from multiple sources: symmetric keys (CK, IK) and physical layer channel information (reference signals, channel state information). This composite approach ensures that even if one component is compromised, the overall key security remains intact.

Inventive Principle:
Principle #40Composite materials

2Reliability

If physical layer channel information is used for key derivation, then security against USIM compromise is improved, but the key generation complexity increases

Engineering Contradiction:
Improvesecurity against USIM compromiseVSAvoidkey derivation process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces key derivation functions (KDFs) as intermediary mechanisms that process both symmetric keys and physical layer channel information to generate the final NAS keys. These KDFs act as mediators that securely combine the inputs while managing the complexity of the derivation process through standardized cryptographic functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameters used in key derivation by incorporating physical layer measurements (reference signal received power, channel state information) alongside traditional symmetric keys. This parameter expansion enhances security against USIM compromise while using well-established cryptographic parameter transformation techniques.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If perfect forward secrecy is implemented through multiple key sources, then long-term security is improved, but the computational overhead increases

Engineering Contradiction:
Improvelong-term securityVSAvoidcomputational overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent performs preliminary key derivation by generating NAS keys from multiple sources during the initial network attachment and authentication phases. This preliminary action ensures that secure keys are established before any data transmission occurs, enabling perfect forward secrecy without requiring complex real-time computations during ongoing communications.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements periodic key refreshment by re-deriving NAS keys at regular intervals or upon specific events (handover, authentication updates). This periodic action maintains long-term security through perfect forward secrecy while allowing the system to reuse established cryptographic algorithms, thereby controlling computational overhead.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS20260040066A1Keys from wireless channel in cellular system non-access stratum layer
Publication Date: 2026.02.05 APPLE INC
  • US20260040066A1 patent drawing
  • US20260040066A1 patent drawing
  • US20260040066A1 patent drawing

AI summary

The present application relates to devices and components including apparatus, systems, and methods to provide configuration of enhanced physical layer security key generation.