Pairwise Master Key Refresh via Challenge Response Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing IEEE 802.16e standard requires a time-consuming and resource-intensive three-party, four-phase authentication procedure to refresh secret symmetric keys, leading to prolonged security associations that increase security risks due to static key values, making them vulnerable to attacks.
Innovation Solution
A method to modify secret symmetric keys using an existing security key, specifically by generating a challenge response message and validating it using a hash function, allowing for periodic refreshment of security associations without accessing the authentication server, thereby reducing the need for the full authentication procedure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the three-party, four-phase authentication procedure is used to refresh secret symmetric keys, then security association is maintained, but the process becomes time-consuming and resource-intensive
Solution Approach 1:
The patent segments the key refresh process into two distinct modes: full authentication mode (four-phase) and fast re-authentication mode (two-phase). This segmentation allows the system to choose the appropriate level of security and computational overhead based on whether the mobile unit is in coverage or out of coverage, resolving the contradiction between maintaining security and reducing time consumption.
Solution Approach 2:
The patent performs preliminary actions by pre-establishing security associations and storing authentication credentials before the mobile unit goes out of coverage. This preliminary preparation enables fast re-authentication to occur without requiring full authentication procedures, thus reducing key refresh time while maintaining security.
2Reliability
If the three-party, four-phase authentication procedure is used to refresh secret symmetric keys, then security association is maintained, but system resources are consumed excessively
Solution Approach 1:
The patent segments the authentication process into full authentication and fast re-authentication phases, allowing the system to use resource-intensive full authentication only when necessary (when out of coverage), and resource-efficient fast re-authentication when in coverage, thus reducing overall system resource consumption while maintaining security.
Solution Approach 2:
The patent applies partial authentication action by implementing a two-phase fast re-authentication process that uses only a subset of the full four-phase authentication procedures. This partial action is sufficient to maintain security associations when the mobile unit is in coverage, avoiding the excessive resource consumption of complete re-authentication.
3Productivity
If secret symmetric keys are kept static for extended periods, then authentication efficiency is improved, but security risks increase due to vulnerability to attacks
Solution Approach 1:
The patent implements periodic key refreshment through fast re-authentication procedures that occur regularly when the mobile unit is in coverage. This periodic action updates secret symmetric keys at appropriate intervals, maintaining authentication efficiency while preventing security vulnerabilities that would arise from excessively static keys.
Solution Approach 2:
The patent introduces dynamics to the key management system by enabling automatic, periodic key refreshment through fast re-authentication when in coverage, while allowing keys to remain stable during out-of-coverage periods. This dynamic approach balances authentication efficiency with security by adapting key stability to operational conditions.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This approach enables efficient and frequent refreshment of secret symmetric keys, decreasing security risks and system resource consumption, while maintaining secure communication without relying on the authentication server for key updates.
Implementation Method 1
generating a challenge response message and validating it using a hash function
Data Source
AI summary
The present invention provides a method for communication involving a supplicant, an authenticator, and an authentication server having an established security association based on a first key. The supplicant and the authenticator also have an established security association based on a second key. The method may include modifying the second key using the first key in response to determining that a challenge response from the supplicant is valid.


