Private Network Security Parameter Derivation Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In industrial scenarios, the security of private network service data cannot be ensured when a private network and a public network share a radio access network and a core network, as the derivation of air interface user plane keys depends on root keys from the public network, exposing security vulnerabilities.

Innovation Solution

A method where a network element of the private network derives a first security parameter using a root key specific to the private network, which is then sent to an access network device, ensuring that the air interface user plane key is generated independently of the public network, thereby isolating the user plane from the public network and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If a private network and a public network share a radio access network and a core network, then cost is reduced, but security of private network service data cannot be ensured

Engineering Contradiction:
Improvedeployment costVSAvoidsecurity of private network service data
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent segments the key management architecture by introducing a separate private network AMF that independently manages security parameters for the private network. This segmentation allows the private network to have its own root key (K_AMF_NPN) and security parameter derivation process, isolating it from the public network's key management while sharing the radio access network infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The private network AMF acts as an intermediary between the terminal device and the access network device for security parameter management. It receives the root key from the terminal device, derives the first security parameter (K_gnb_NPN), and provides it to the access network device, thereby mediating the security function while enabling network sharing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If the air interface user plane key is derived from public network root keys, then key derivation is simplified, but security vulnerabilities are exposed

Engineering Contradiction:
Improvekey derivation complexityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by creating a dedicated security parameter derivation path for the private network. The first security parameter (K_gnb_NPN) is derived specifically for NPN user plane encryption using the private network's root key, ensuring that private network security parameters have different quality characteristics (independence and confidentiality) from public network parameters.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent extracts the security parameter derivation function for the private network from the public network's key management process. By having the private network AMF independently derive K_gnb_NPN from the private network root key, it separates the private network's security requirements from the public network's key hierarchy, eliminating the security vulnerability of key exposure.

Inventive Principle:
Principle #2Taking out (Extraction)

3Device complexity

If the root key is shared between private and public networks, then key management is simplified, but the root key security is compromised

Engineering Contradiction:
Improvekey management complexityVSAvoidroot key security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the root key into network-specific keys: a public network root key (K_AMF) for public network services and a private network root key (K_AMF_NPN) for private network services. The terminal device stores and provides the appropriate root key based on the network type, ensuring that private network root keys remain confidential and are not exposed to the public network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Instead of the access network device deriving security parameters from the AMF (as in traditional architecture), the patent inverts the flow by having the terminal device provide the root key to the AMF, which then derives and provides the first security parameter to the access network device. This inversion ensures that the root key remains in the control plane and is not exposed in the user plane.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentEP4274282B1Method, apparatus and system for obtaining security parameters
Publication Date: 2025.01.01 HUAWEI TECH CO LTD
  • EP4274282B1 patent drawingFigure 1
  • EP4274282B1 patent drawingFigure 2~3
  • EP4274282B1 patent drawingFigure 4

AI summary

This application discloses a security parameter obtaining method, an apparatus, and a system, to ensure security of a private network service. In this application, security parameters used to derive an air interface control plane key and an air interface user plane key are separately generated, the security parameter used to derive the air interface user plane key is derived by using a root key of a private network, and derivation is completed in the private network, to prevent the root key of the private network and a process of deriving the security parameter from being exposed in a public network. In this way, when the air interface user plane key is used to securely transmit service data, security of service data transmission over an air interface can be improved.