Next Generation Key Set Identifier for 5G Security Contexts

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The next generation 5G wireless communication systems require a clear identification of key sets for managing and accessing security contexts and key hierarchies, especially during authentication and key agreement protocols, to ensure backward compatibility and secure non-access stratum communication across multiple access technologies.

Innovation Solution

A Next Generation Key Set Identifier (NG-KSI) is introduced, which is associated with a master key derived during authentication and key agreement protocols, allowing for the instantiation of a security context and secure communication between user equipment and network nodes, including additional parameters to support unified authentication across various access technologies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a unified security context identification mechanism is implemented across multiple access technologies, then backward compatibility and secure non-access stratum communication are improved, but device complexity increases due to the need to manage multiple key sets and authentication protocols

Engineering Contradiction:
Improvebackward compatibilityVSAvoidsecurity context management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The NG-KSI is designed as a universal security context identification mechanism that works across multiple access technologies (5G NR, LTE, Wi-Fi, Bluetooth). The identifier structure includes a type field that indicates the access technology, allowing a single identification mechanism to serve multiple functions and maintain backward compatibility while managing diverse key sets

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The NG-KSI is segmented into distinct fields: a type field indicating the access technology (5G, LTE, Wi-Fi, Bluetooth) and a value field containing the actual key set identifier. This segmentation allows the system to manage multiple key sets independently while using a unified identification structure, reducing the complexity of managing security contexts across different technologies

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If additional parameters are included in security mode command messages to support unified authentication, then adaptability across access technologies is improved, but message complexity and processing overhead increase

Engineering Contradiction:
Improveunified authentication supportVSAvoidmessage processing
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The security mode command message includes additional parameters specifically tailored to the indicated access technology type. The message structure adapts locally based on the NG-KSI type field, including only the necessary parameters for each technology (5G, LTE, Wi-Fi, Bluetooth), thereby providing unified authentication support without unnecessarily increasing message complexity for all technologies

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11889304B2Next generation key set identifier
Publication Date: 2024.01.30 NOKIA SOLUTIONS & NETWORKS OY
  • US11889304B2 patent drawing
  • US11889304B2 patent drawing
  • US11889304B2 patent drawing

AI summary

Systems, methods, apparatuses, and computer program products directed to next generation (e.g., 5G systems) key set identifier(s) are provided. One method includes requesting, by a network node, authentication of a user equipment with an authentication server, receiving a master key and authentication parameters/vectors from the authentication server when authorization is successful, and verifying validity of the authentication request. When the verification is successful, the method may further include instantiating a security context for the user equipment and assigning a security context identifier for next generation system security context to the user equipment, and then sending a security mode command message to instruct the user equipment to instantiate security context using the security context identifier.