On-Demand Network Function Re-Authentication via Key Refresh
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication systems face inefficiencies and security concerns due to the prolonged storage of security contexts, which can be compromised, leading to resource wastage and potential impersonation attacks.
Innovation Solution
A UE initiates a key refresh procedure by identifying a parent network node through a key hierarchy and transmitting a key refresh request, triggering a key refresh between the parent network node and the network node to establish a new security context.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of energy
If security context is stored for extended period to avoid frequent re-authentication, then resource consumption is reduced, but security risk increases due to potential key compromise
Solution Approach 1:
The patent implements periodic key refresh procedures where the UE initiates re-authentication at predetermined intervals rather than continuously or only upon connection. This periodic action maintains security by regularly updating keys while minimizing resource consumption by keeping the security context stored during intervals, directly resolving the contradiction between extended storage and security risk
2Reliability
If new security context is established each time device sends traffic, then security is maintained, but resource consumption and battery power increase
Solution Approach 1:
Instead of establishing new security contexts with every traffic transmission, the system uses periodic key refresh at predetermined intervals. This approach maintains security by regularly updating keys while significantly reducing the frequency of full re-authentication procedures, thereby conserving battery power and network resources
Solution Approach 2:
The security context is established in advance and stored for future use during predetermined intervals. This preliminary action allows the device to send traffic without immediate re-authentication, reducing energy consumption while maintaining security through pre-established authentication credentials
3Productivity
If security context is maintained at network nodes, then connection efficiency is improved, but vulnerability to impersonation attacks increases
Solution Approach 1:
The patent implements periodic key refresh procedures that update security contexts at predetermined intervals while maintaining them stored between updates. This approach preserves connection efficiency by avoiding frequent re-establishment of security contexts while mitigating impersonation risks through regular key rotation, directly addressing the contradiction between efficiency and security vulnerability
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Methods, systems, and devices for wireless communication are described. A user equipment (UE) may determine that a security context with a network node has been established for more than a threshold time period. The UE may identify, based on a key hierarchy, a parent network node associated with the network node. The UE may transmit a key refresh request message to the parent network node to trigger a key refresh procedure between the parent network node and the network node. The UE may perform a procedure with the network node to establish a new security context based on the key refresh procedure.