Horizontal NAS Key Derivation for Wireless Network Security Refresh
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication networks face challenges in robustly refreshing Non-Access Stratum (NAS) keys while maintaining low signaling overhead, especially when transitioning between different generations of wireless communication networks.
Innovation Solution
The method involves horizontal key derivation, where a new base key is derived from the current base key using a key derivation function that incorporates a NAS count, allowing for the refresh of NAS keys without running primary authentication procedures, and activating this new base key to establish a new security context, thereby efficiently managing key changes across different wireless communication networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If primary authentication procedures are run to refresh NAS keys, then key security is improved, but signaling overhead increases
Solution Approach 1:
The patent extracts the essential key refresh function from the complete primary authentication procedure. Instead of running full authentication, it uses a simplified key derivation process that derives new NAS keys from existing base keys, removing unnecessary authentication steps while retaining security benefits
Solution Approach 2:
The patent performs preliminary key derivation by deriving a new base key from the current base key before NAS key refresh is actually needed. This proactive approach ensures keys are ready for refresh without requiring time-consuming authentication procedures when refresh is triggered
2Reliability
If NAS keys are refreshed frequently, then security against key re-use is improved, but signaling overhead increases
Solution Approach 1:
The patent changes the parameter used for key derivation from static authentication credentials to dynamic parameters including NAS count values. This allows frequent key refresh based on usage counters without requiring repeated authentication, as keys are derived from changing parameters rather than re-authenticating
3Loss of information
If horizontal key derivation is used to refresh NAS keys, then signaling overhead is reduced, but compatibility with future network generations must be maintained
Solution Approach 1:
The patent creates a universal key derivation mechanism that can function across different network generations. The horizontal key derivation process using base keys and NAS counts is designed to be generation-agnostic, allowing the same mechanism to work in current 5G networks and future 6G networks without requiring protocol changes
4Productivity
If NAS count is used in key derivation, then key refresh timing is optimized, but complexity of key management increases
Solution Approach 1:
The patent implements self-service key management where the system automatically tracks NAS count values and triggers key refresh when thresholds are reached. The key derivation process automatically incorporates NAS count parameters, eliminating the need for manual intervention or complex external key management systems
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Network equipment (16A) is configured for use in a wireless communication network. The network equipment (16A) is configured to detect one or more conditions under which non-access stratum (NAS) keys (26 A) that protect NAS communication between the network equipment (16A) and a wireless device (12) are to be refreshed. Responsive to detecting the one or more conditions, the network equipment (16A) is configured to derive, from a base key (24A) on which the NAS keys (26 A) were derived, a new base key (24 B) on which fresh NAS keys (26B) are to be derived. The network equipment (16A) is also configured to activate the new base key (24B).