Network Slice Key Derivation Using Unique Intermediate Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In mobile communication systems, different network slices often use the same intermediate key, leading to failure in implementing slice functions effectively due to key sharing across slices.

Innovation Solution

A key derivation method and device that acquire and transmit a slice identifier to a designated communication device, enabling the derivation of a unique intermediate key required by each network slice, ensuring distinct keys for different slices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If the same intermediate key is used across different network slices, then key management is simplified, but slice function implementation fails due to key sharing

Engineering Contradiction:
Improvekey management complexityVSAvoidslice function implementation
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the key management system by introducing slice-specific parameters (slice ID, network slice identifier) into the key derivation process. This divides the previously unified key management into slice-isolated key spaces, where each network slice derives its own unique intermediate key from the same root key material, ensuring both simplified root key management and slice-specific key isolation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by making the key derivation process slice-specific through local parameters. While the root key remains the same across slices, the intermediate key derivation incorporates slice-identifying parameters, creating locally unique keys for each slice. This allows different parts of the system (different slices) to have different key qualities while maintaining a unified root key structure.

Inventive Principle:
Principle #3Local quality

2Reliability

If unique intermediate keys are derived for each network slice, then slice isolation is achieved, but key management complexity increases

Engineering Contradiction:
Improveslice isolationVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary action by pre-defining the slice-identifying parameters and key derivation relationships before actual slice operation. The system establishes the mapping between slice identifiers and their corresponding key derivation parameters in advance, so that when slices are activated, their unique keys are automatically derived without complex real-time key management operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism through the use of slice identifiers and network slice parameters that mediate between the root key and slice-specific intermediate keys. This intermediary layer simplifies key management by providing a systematic way to generate unique slice keys without requiring separate key distribution channels or complex key management protocols for each slice.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11290876B2Key derivation method and apparatus
Publication Date: 2022.03.29 XIAN ZHONGXING NEW SOFTWARE
  • US11290876B2 patent drawing
  • US11290876B2 patent drawing
  • US11290876B2 patent drawing

AI summary

Provided are a key derivation method and device. The method includes: acquiring a slice identifier corresponding to a network slice to which a user equipment is currently attached, where the slice identifier uniquely identifies the network slice; and transmitting the slice identifier to a designated communication device. The slice identifier is configured to instruct the designated communication device to derive, according to the slice identifier, an intermediate key required by the network slice. By means of the technical solution described above, the problem in the related art that a slice function cannot be implemented normally due to the fact that different network slices probably use the same intermediate key may be solved, and different network slices may correspond to different intermediate keys, thereby avoiding a case that the slicing function cannot be implemented normally caused by allocating the same intermediate key to different network slices.