Pairwise Master Key Refresh via Challenge Response Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing IEEE 802.16e standard requires a time-consuming and resource-intensive three-party, four-phase authentication procedure to refresh secret symmetric keys, leading to prolonged security associations that increase security risks due to static key values, making them vulnerable to attacks.

Innovation Solution

A method to modify secret symmetric keys using an existing security key, specifically by generating a challenge response message and validating it using a hash function, allowing for periodic refreshment of security associations without accessing the authentication server, thereby reducing the need for the full authentication procedure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the three-party, four-phase authentication procedure is used to refresh secret symmetric keys, then security association is maintained, but the process becomes time-consuming and resource-intensive

Engineering Contradiction:
Improvesecurity associationVSAvoidkey refresh time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the key refresh process into two distinct modes: full authentication mode (four-phase) and fast re-authentication mode (two-phase). This segmentation allows the system to choose the appropriate level of security and computational overhead based on whether the mobile unit is in coverage or out of coverage, resolving the contradiction between maintaining security and reducing time consumption.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary actions by pre-establishing security associations and storing authentication credentials before the mobile unit goes out of coverage. This preliminary preparation enables fast re-authentication to occur without requiring full authentication procedures, thus reducing key refresh time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the three-party, four-phase authentication procedure is used to refresh secret symmetric keys, then security association is maintained, but system resources are consumed excessively

Engineering Contradiction:
Improvesecurity associationVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the authentication process into full authentication and fast re-authentication phases, allowing the system to use resource-intensive full authentication only when necessary (when out of coverage), and resource-efficient fast re-authentication when in coverage, thus reducing overall system resource consumption while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial authentication action by implementing a two-phase fast re-authentication process that uses only a subset of the full four-phase authentication procedures. This partial action is sufficient to maintain security associations when the mobile unit is in coverage, avoiding the excessive resource consumption of complete re-authentication.

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If secret symmetric keys are kept static for extended periods, then authentication efficiency is improved, but security risks increase due to vulnerability to attacks

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements periodic key refreshment through fast re-authentication procedures that occur regularly when the mobile unit is in coverage. This periodic action updates secret symmetric keys at appropriate intervals, maintaining authentication efficiency while preventing security vulnerabilities that would arise from excessively static keys.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent introduces dynamics to the key management system by enabling automatic, periodic key refreshment through fast re-authentication when in coverage, while allowing keys to remain stable during out-of-coverage periods. This dynamic approach balances authentication efficiency with security by adapting key stability to operational conditions.

Inventive Principle:
Principle #15Dynamics

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach enables efficient and frequent refreshment of secret symmetric keys, decreasing security risks and system resource consumption, while maintaining secure communication without relying on the authentication server for key updates.

Implementation Method 1

generating a challenge response message and validating it using a hash function

Methodology Applied
Scientific EffectHash function:

Data Source

PatentUS7596225B2Method for refreshing a pairwise master key
Publication Date: 2009.09.29 NOKIA OF AMERICA CORP
  • US7596225B2 patent drawing
  • US7596225B2 patent drawing
  • US7596225B2 patent drawing

AI summary

The present invention provides a method for communication involving a supplicant, an authenticator, and an authentication server having an established security association based on a first key. The supplicant and the authenticator also have an established security association based on a second key. The method may include modifying the second key using the first key in response to determining that a challenge response from the supplicant is valid.