Horizontal NAS Key Derivation for Wireless Network Security Refresh

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication networks face challenges in robustly refreshing Non-Access Stratum (NAS) keys while maintaining low signaling overhead, especially when transitioning between different generations of wireless communication networks.

Innovation Solution

The method involves horizontal key derivation, where a new base key is derived from the current base key using a key derivation function that incorporates a NAS count, allowing for the refresh of NAS keys without running primary authentication procedures, and activating this new base key to establish a new security context, thereby efficiently managing key changes across different wireless communication networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If primary authentication procedures are run to refresh NAS keys, then key security is improved, but signaling overhead increases

Engineering Contradiction:
Improvekey securityVSAvoidsignaling overhead
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts the essential key refresh function from the complete primary authentication procedure. Instead of running full authentication, it uses a simplified key derivation process that derives new NAS keys from existing base keys, removing unnecessary authentication steps while retaining security benefits

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs preliminary key derivation by deriving a new base key from the current base key before NAS key refresh is actually needed. This proactive approach ensures keys are ready for refresh without requiring time-consuming authentication procedures when refresh is triggered

Inventive Principle:
Principle #10Preliminary action

2Reliability

If NAS keys are refreshed frequently, then security against key re-use is improved, but signaling overhead increases

Engineering Contradiction:
Improveprotection against key re-useVSAvoidsignaling overhead
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent changes the parameter used for key derivation from static authentication credentials to dynamic parameters including NAS count values. This allows frequent key refresh based on usage counters without requiring repeated authentication, as keys are derived from changing parameters rather than re-authenticating

Inventive Principle:
Principle #35Parameter changes

3Loss of information

If horizontal key derivation is used to refresh NAS keys, then signaling overhead is reduced, but compatibility with future network generations must be maintained

Engineering Contradiction:
Improvesignaling overheadVSAvoidcompatibility with future networks
Core Design Contradiction:
Loss of informationVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal key derivation mechanism that can function across different network generations. The horizontal key derivation process using base keys and NAS counts is designed to be generation-agnostic, allowing the same mechanism to work in current 5G networks and future 6G networks without requiring protocol changes

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Productivity

If NAS count is used in key derivation, then key refresh timing is optimized, but complexity of key management increases

Engineering Contradiction:
Improvekey refresh efficiencyVSAvoidkey management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements self-service key management where the system automatically tracks NAS count values and triggers key refresh when thresholds are reached. The key derivation process automatically incorporates NAS count parameters, eliminating the need for manual intervention or complex external key management systems

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3837873B1Protection of non-access stratum communication in a wireless communication network
Publication Date: 2024.07.31 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP3837873B1 patent drawingFigure 1
  • EP3837873B1 patent drawingFigure 2
  • EP3837873B1 patent drawingFigure 3

AI summary

Network equipment (16A) is configured for use in a wireless communication network. The network equipment (16A) is configured to detect one or more conditions under which non-access stratum (NAS) keys (26 A) that protect NAS communication between the network equipment (16A) and a wireless device (12) are to be refreshed. Responsive to detecting the one or more conditions, the network equipment (16A) is configured to derive, from a base key (24A) on which the NAS keys (26 A) were derived, a new base key (24 B) on which fresh NAS keys (26B) are to be derived. The network equipment (16A) is also configured to activate the new base key (24B).