On-Demand Network Function Re-Authentication via Key Refresh

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication systems face inefficiencies and security concerns due to the prolonged storage of security contexts, which can be compromised, leading to resource wastage and potential impersonation attacks.

Innovation Solution

A UE initiates a key refresh procedure by identifying a parent network node through a key hierarchy and transmitting a key refresh request, triggering a key refresh between the parent network node and the network node to establish a new security context.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of energy

If security context is stored for extended period to avoid frequent re-authentication, then resource consumption is reduced, but security risk increases due to potential key compromise

Engineering Contradiction:
Improveresource consumptionVSAvoidsecurity risk
Core Design Contradiction:
Loss of energyVSReliability

Solution Approach 1:

The patent implements periodic key refresh procedures where the UE initiates re-authentication at predetermined intervals rather than continuously or only upon connection. This periodic action maintains security by regularly updating keys while minimizing resource consumption by keeping the security context stored during intervals, directly resolving the contradiction between extended storage and security risk

Inventive Principle:
Principle #19Periodic action

2Reliability

If new security context is established each time device sends traffic, then security is maintained, but resource consumption and battery power increase

Engineering Contradiction:
ImprovesecurityVSAvoidbattery power
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

Instead of establishing new security contexts with every traffic transmission, the system uses periodic key refresh at predetermined intervals. This approach maintains security by regularly updating keys while significantly reducing the frequency of full re-authentication procedures, thereby conserving battery power and network resources

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The security context is established in advance and stored for future use during predetermined intervals. This preliminary action allows the device to send traffic without immediate re-authentication, reducing energy consumption while maintaining security through pre-established authentication credentials

Inventive Principle:
Principle #10Preliminary action

3Productivity

If security context is maintained at network nodes, then connection efficiency is improved, but vulnerability to impersonation attacks increases

Engineering Contradiction:
Improveconnection efficiencyVSAvoidimpersonation attack risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements periodic key refresh procedures that update security contexts at predetermined intervals while maintaining them stored between updates. This approach preserves connection efficiency by avoiding frequent re-establishment of security contexts while mitigating impersonation risks through regular key rotation, directly addressing the contradiction between efficiency and security vulnerability

Inventive Principle:
Principle #19Periodic action

Data Source

PatentEP3513585B1On-demand network function re-authentication based on key refresh
Publication Date: 2025.09.17 QUALCOMM INC
  • EP3513585B1 patent drawingFigure 1
  • EP3513585B1 patent drawingFigure 2
  • EP3513585B1 patent drawingFigure 3

AI summary

Methods, systems, and devices for wireless communication are described. A user equipment (UE) may determine that a security context with a network node has been established for more than a threshold time period. The UE may identify, based on a key hierarchy, a parent network node associated with the network node. The UE may transmit a key refresh request message to the parent network node to trigger a key refresh procedure between the parent network node and the network node. The UE may perform a procedure with the network node to establish a new security context based on the key refresh procedure.