PCF–UE Policy Messaging With Derived Encryption And Integrity Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing wireless network systems face security vulnerabilities due to the lack of integrity and encryption in policy control function (PCF) communications with user equipment (UE), leading to potential attacks, unauthorized modifications, and compromised quality of service issues.

Innovation Solution

Implementing secure policy messaging by deriving a PCF device key from a master session key, generating integrity and encryption keys, and encrypting policy information within the PCF device, ensuring that the UE can validate and decrypt the information independently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If policy information is transmitted without encryption and integrity protection, then device complexity and processing overhead are reduced, but security is compromised allowing attacks and unauthorized modifications

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-establishing security contexts and deriving encryption/integrity keys before policy information transmission. The PCF device and UE perform key derivation from master session keys, establish security contexts, and prepare encryption/integrity protection mechanisms in advance, so that when policy information needs to be transmitted, the security framework is already in place and can be applied efficiently without adding significant processing overhead during the actual policy delivery.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If encryption and integrity protection are implemented in policy messaging, then security is improved, but processing overhead and complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements universality by creating a multi-functional security context that serves multiple purposes. The same security context and derived keys are used for both encryption and integrity protection of policy information. This unified approach allows the system to achieve comprehensive security (confidentiality and authenticity) using a single security framework, reducing the need for separate processing mechanisms and thereby lowering overall processing overhead compared to implementing multiple independent security layers.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If no integrity protection is provided, then message modification is easier and device complexity is reduced, but unauthorized modifications and attacks become possible

Engineering Contradiction:
ImproveintegrityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary mechanism in the form of integrity protection codes (such as MACs - Message Authentication Codes) that are generated and verified using shared secret keys. This intermediary integrity check serves as a mediator between the transmitting and receiving parties, providing cryptographic proof that the policy information has not been modified. The intermediary mechanism adds minimal complexity compared to the alternative of no integrity protection, as it uses efficient cryptographic algorithms that can be implemented with relatively simple processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If policy information is sent without encryption, then transmission simplicity is maintained, but confidentiality is compromised allowing eavesdropping and attacks

Engineering Contradiction:
ImproveconfidentialityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by dynamically selecting and applying encryption parameters based on the security context and service requirements. The encryption strength, algorithm selection, and key derivation parameters are adjusted according to the specific policy information being transmitted and the security level required. This parameter-based approach allows the system to achieve strong confidentiality when needed while avoiding the overhead of maximum-strength encryption for all policy messages, thereby balancing security with manageable complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250337592A1Systems and methods for secure policy messaging
Publication Date: 2025.10.30 VERIZON PATENT & LICENSING INC
  • US20250337592A1 patent drawing
  • US20250337592A1 patent drawing
  • US20250337592A1 patent drawing

AI summary

In some implementations, a policy control function (PCF) device may receive a PCF device key uniquely associated with a user equipment (UE). The PCF device may generate an integrity key and an encryption key based on the PCF device key and an identifier of the PCF device. The PCF device may generate, based on the integrity key, integrity data associated with policy information related to the UE. The PCF device may encrypt, based on the encryption key, the policy information to generate encrypted policy information. The PCF device may send, for the UE, a UE policy message indicating the integrity data, the encrypted policy information, and the identifier of the PCF device.