PLMN Public Key Distribution via Core Network Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cellular systems, distributing the public key of a Public Land Mobile Network (PLMN) to a terminal is challenging, especially when the terminal and network mutually validate each other's identity during the 3GPP authentication and key agreement process, as previous methods rely on a certification authority which may not be accessible.

Innovation Solution

The solution involves a core network function providing the public key of the PLMN to the terminal after mutual authentication, using the NAS key established during the security mode command procedure, allowing the terminal to securely store and use the public key for integrity protection, and optionally updating or revoking it as needed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a certification authority is used to distribute public keys, then key distribution can be achieved, but the system complexity increases and the CA may not be accessible to terminals

Engineering Contradiction:
Improvekey distribution reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the public key distribution function from the traditional certification authority model and integrates it directly into the core network function. The core network function autonomously provides the PLMN public key to the terminal without requiring a separate CA infrastructure, thereby reducing system complexity while maintaining distribution reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent merges the public key distribution function with the existing core network function and authentication procedures. The public key is provided during the authentication process itself, combining multiple functions (authentication and key distribution) into a single integrated process, eliminating the need for separate CA infrastructure.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If public key is provided frequently to ensure security, then security is improved, but the time consumption and overhead increase

Engineering Contradiction:
Improvecommunication securityVSAvoidkey update time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by providing the PLMN public key to the terminal during the initial authentication process and storing it in the terminal's non-volatile memory. This preliminary provision of the public key eliminates the need for frequent subsequent key updates, as the terminal retains the public key for ongoing security operations without requiring continuous retransmission.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If mutual authentication is performed before key distribution, then security is improved, but the authentication process complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the public key distribution function with the mutual authentication procedure. The core network function provides the PLMN public key to the terminal as part of the authentication process itself, combining authentication and key distribution into a single integrated flow, thereby avoiding additional complexity from separate authentication steps.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3902300B1Prohibiting inefficient distribution of public keys from the public land mobile network
Publication Date: 2023.08.30 NOKIA TECHNOLOGIES OY
  • EP3902300B1 patent drawingFigure 1
  • EP3902300B1 patent drawingFigure 2
  • EP3902300B1 patent drawingFigure 3

AI summary

An apparatus comprising: at least one processor; and at least one memory including computer program code; the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus at least to: receive (600) a message from a terminal in a public land mobile network, wherein the message comprises at least one indication indicating whether a public key of the public land mobile network is to be provided to the terminal; and determine (602) whether to provide the public key of the public land mobile network to the terminal based on the at least one indication.