PCF–UE Policy Messaging With Derived Encryption And Integrity Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing wireless network systems face security vulnerabilities due to the lack of integrity and encryption in policy control function (PCF) communications with user equipment (UE), leading to potential attacks, unauthorized modifications, and compromised quality of service issues.
Innovation Solution
Implementing secure policy messaging by deriving a PCF device key from a master session key, generating integrity and encryption keys, and encrypting policy information within the PCF device, ensuring that the UE can validate and decrypt the information independently.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If policy information is transmitted without encryption and integrity protection, then device complexity and processing overhead are reduced, but security is compromised allowing attacks and unauthorized modifications
Solution Approach 1:
The patent applies preliminary action by pre-establishing security contexts and deriving encryption/integrity keys before policy information transmission. The PCF device and UE perform key derivation from master session keys, establish security contexts, and prepare encryption/integrity protection mechanisms in advance, so that when policy information needs to be transmitted, the security framework is already in place and can be applied efficiently without adding significant processing overhead during the actual policy delivery.
2Reliability
If encryption and integrity protection are implemented in policy messaging, then security is improved, but processing overhead and complexity increase
Solution Approach 1:
The patent implements universality by creating a multi-functional security context that serves multiple purposes. The same security context and derived keys are used for both encryption and integrity protection of policy information. This unified approach allows the system to achieve comprehensive security (confidentiality and authenticity) using a single security framework, reducing the need for separate processing mechanisms and thereby lowering overall processing overhead compared to implementing multiple independent security layers.
3Reliability
If no integrity protection is provided, then message modification is easier and device complexity is reduced, but unauthorized modifications and attacks become possible
Solution Approach 1:
The patent introduces an intermediary mechanism in the form of integrity protection codes (such as MACs - Message Authentication Codes) that are generated and verified using shared secret keys. This intermediary integrity check serves as a mediator between the transmitting and receiving parties, providing cryptographic proof that the policy information has not been modified. The intermediary mechanism adds minimal complexity compared to the alternative of no integrity protection, as it uses efficient cryptographic algorithms that can be implemented with relatively simple processing.
4Reliability
If policy information is sent without encryption, then transmission simplicity is maintained, but confidentiality is compromised allowing eavesdropping and attacks
Solution Approach 1:
The patent applies parameter changes by dynamically selecting and applying encryption parameters based on the security context and service requirements. The encryption strength, algorithm selection, and key derivation parameters are adjusted according to the specific policy information being transmitted and the security level required. This parameter-based approach allows the system to achieve strong confidentiality when needed while avoiding the overhead of maximum-strength encryption for all policy messages, thereby balancing security with manageable complexity.
Data Source
AI summary
In some implementations, a policy control function (PCF) device may receive a PCF device key uniquely associated with a user equipment (UE). The PCF device may generate an integrity key and an encryption key based on the PCF device key and an identifier of the PCF device. The PCF device may generate, based on the integrity key, integrity data associated with policy information related to the UE. The PCF device may encrypt, based on the encryption key, the policy information to generate encrypted policy information. The PCF device may send, for the UE, a UE policy message indicating the integrity data, the encrypted policy information, and the identifier of the PCF device.


