Centralized Key Distribution in Next Generation Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current key distribution protocols in Next Generation Networks (NGN) are inefficient and unsuitable for the network's centralized management structure, leading to increased traffic and management inconvenience due to direct key negotiations between terminals and devices.
Innovation Solution
A centralized key distribution method involving a terminal, a soft switch, and an authentication center, where the authentication center generates and distributes session keys during registration authentication, reducing the need for subsequent key negotiations and combining registration and security mechanism negotiation processes with existing protocols like SIP, MGCP, H.248, and H.323.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If direct key negotiation between terminals or mainframes is used, then key distribution can be achieved, but system traffic grows in geometric progression and key distribution efficiency is degraded
Solution Approach 1:
The patent introduces a key distribution center (KDC) as an intermediary entity that performs key negotiation between terminals and network devices. The KDC receives key requests from terminals, generates session keys, and distributes them to both the terminal and network device, thereby eliminating direct key negotiation traffic between terminals and network devices while maintaining secure key distribution.
Solution Approach 2:
The patent segments the key distribution function from the communication function by introducing a dedicated key distribution center. This segmentation allows key management operations to be separated from data communication, enabling efficient key distribution without increasing overall system traffic. The KDC handles key generation and distribution independently, reducing the burden on communication channels.
2Reliability
If standardized key distribution protocols like IKE or Handshake are used, then security can be ensured, but the protocols fail to incorporate NGN characteristics and require complex negotiation processes
Solution Approach 1:
The patent adapts key distribution to match the specific characteristics of NGN by implementing a centralized approach tailored to the network's hierarchical structure. The key distribution center operates with specific functions suited to NGN requirements, such as integrating with authentication centers and soft switches, thereby providing security that is both robust and locally optimized for NGN characteristics.
Solution Approach 2:
The patent merges key distribution with existing NGN authentication and registration processes. The key distribution center integrates with the authentication center and soft switch to perform key negotiation during the registration process, combining multiple functions (authentication, registration, and key distribution) into a unified process, thereby reducing overall system complexity while maintaining security.
3Productivity
If centralized key distribution is implemented, then key distribution efficiency improves and traffic is reduced, but the system requires integration with existing protocols like SIP, MGCP, H.248, and H.323
Solution Approach 1:
The key distribution center is designed with universal functionality to support multiple communication protocols including SIP, MGCP, H.248, and H.323. It can perform key distribution operations across different protocol frameworks, making the centralized system adaptable to various NGN deployment scenarios and communication standards without requiring separate implementations for each protocol.
Data Source
AI summary
A key distribution method for the next generation network (NGN), includes steps of: (a) a terminal sending a registration request message to a soft switch; (b) the soft switch sending an authentication request message to an authentication center; (c) the authentication center authenticating the terminal, then the soft switch distributing the session key to the terminal after the registration authentication being passed. The invention implements the key distribution during the registration authentication, thus the traffic is smaller, and it could be associated with the specialties of the NGN, and improve the efficiency of solving the security problem, the registration authentication of the terminal and the distribution of the key are more suitable specifically for the NGN.


