NAS Key Derivation Using Wireless Channel Data for Forward Secrecy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Legacy approaches for generating non-access stratum (NAS) keys in wireless networks are insecure when the universal subscriber identity module (USIM) is compromised, leading to vulnerabilities in key security.
Innovation Solution
Implementing perfect forward secrecy (PFS) by deriving NAS keys using both symmetric keys and physical layer channel information, ensuring secure key generation even if the USIM is compromised.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If NAS keys are generated using only symmetric keys from USIM, then the key generation process is simple, but the security is compromised when USIM is compromised
Solution Approach 1:
The patent combines symmetric keys from USIM with physical layer channel information to generate NAS keys. This merging of two different key sources creates a more secure key generation process where compromise of one source (USIM) does not lead to complete key compromise, thus resolving the security vulnerability while maintaining reasonable process complexity.
Solution Approach 2:
The patent creates a composite key structure by deriving NAS keys from multiple sources: symmetric keys (CK, IK) and physical layer channel information (reference signals, channel state information). This composite approach ensures that even if one component is compromised, the overall key security remains intact.
2Reliability
If physical layer channel information is used for key derivation, then security against USIM compromise is improved, but the key generation complexity increases
Solution Approach 1:
The patent introduces key derivation functions (KDFs) as intermediary mechanisms that process both symmetric keys and physical layer channel information to generate the final NAS keys. These KDFs act as mediators that securely combine the inputs while managing the complexity of the derivation process through standardized cryptographic functions.
Solution Approach 2:
The patent changes the parameters used in key derivation by incorporating physical layer measurements (reference signal received power, channel state information) alongside traditional symmetric keys. This parameter expansion enhances security against USIM compromise while using well-established cryptographic parameter transformation techniques.
3Reliability
If perfect forward secrecy is implemented through multiple key sources, then long-term security is improved, but the computational overhead increases
Solution Approach 1:
The patent performs preliminary key derivation by generating NAS keys from multiple sources during the initial network attachment and authentication phases. This preliminary action ensures that secure keys are established before any data transmission occurs, enabling perfect forward secrecy without requiring complex real-time computations during ongoing communications.
Solution Approach 2:
The patent implements periodic key refreshment by re-deriving NAS keys at regular intervals or upon specific events (handover, authentication updates). This periodic action maintains long-term security through perfect forward secrecy while allowing the system to reuse established cryptographic algorithms, thereby controlling computational overhead.
Data Source
AI summary
The present application relates to devices and components including apparatus, systems, and methods to provide configuration of enhanced physical layer security key generation.


