Relay Node Attribute Verification via Local Entity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The introduction of Relay Nodes in the Evolved Packet System (EPS) architecture poses new security challenges, as the Mobility Management Entity (MME-RN) lacks the means to directly verify the attributes of Relay Nodes, which are essential for secure operation and integrity of the platform.

Innovation Solution

An apparatus and method that utilize property checking, key generation, and secure protocol mechanisms to verify the attributes of a claimant device, generating and supplying intermediate keys only if the verification is successful, and securely storing keys to prevent unauthorized access, allowing for remote verification and secure communication within the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the MME-RN directly verifies Relay Node attributes, then network security is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidMME-RN complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a Local Verification Entity (LVE) as an intermediary component within the Relay Node that performs attribute verification locally. The LVE checks whether the RN executes RN-specific functions in a secure environment and verifies platform integrity, then communicates verification results to the MME-RN. This mediator approach allows the MME-RN to verify RN attributes without directly implementing complex verification functionality, thus improving network security while avoiding increased MME-RN device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If verification functionality is enhanced in network entities, then attribute verification capability is improved, but device complexity increases

Engineering Contradiction:
Improveattribute verification capabilityVSAvoidnetwork entity complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the verification functionality by separating it into a dedicated Local Verification Entity (LVE) component within the Relay Node, distinct from the MME-RN. The LVE is specifically responsible for checking RN attributes and platform integrity, while the MME-RN handles mobility management. This segmentation allows precise attribute verification capability to be implemented in the most suitable location without unnecessarily complicating the MME-RN architecture.

Inventive Principle:
Principle #1Segmentation

3Reliability

If secure key generation and supply mechanisms are implemented, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidapparatus complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by having the Local Verification Entity verify Relay Node attributes and generate verification results before the MME-RN performs mobility management operations. The LVE checks whether the RN executes RN-specific functions in a secure environment and establishes platform integrity in advance, so that subsequent security operations can proceed based on pre-verified conditions. This preliminary verification approach improves overall security without requiring the MME-RN to continuously perform complex verification operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10218514B2Remote verification of attributes in a communication network
Publication Date: 2019.02.26 NOKIA TECHNOLOGIES OY
  • US10218514B2 patent drawing
  • US10218514B2 patent drawing
  • US10218514B2 patent drawing

AI summary

It is provided an apparatus, comprising property checking means configured to check whether a claimant property information received from a claimant device corresponds to a predefined claimant attribute; obtaining means configured to obtain a result, which is positive only if the claimant property information corresponds to the predefined claimant attribute as checked by the property checking means; key generation means configured to generate a first claimant intermediate key from a predefined claimant permanent key stored in the apparatus; supplying means configured to supply, to the claimant device, the first claimant intermediate key using a secured protocol, wherein at least one of the key generation means and the supplying means is configured to generate and to supply, respectively, the first claimant intermediate key only if the result is positive.