Relayed Communication Security Key Derivation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for transmitting encrypted information to mobile communication networks require the setup of a secure tunnel with each service separately, which is inefficient and lacks a standardized approach for deriving security keys, especially when devices are handed over between different nodes in a mobile communication network.

Innovation Solution

A device and system that derive security keys based on information related to nodes in the mobile communication network, allowing encrypted information to be transmitted via a further device without establishing a secure tunnel with each service separately, by determining the security key based on the node to which the further device is connected, enabling secure handover and communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a secure tunnel is established with each service separately, then security is maintained, but device complexity and setup time increase

Engineering Contradiction:
ImprovesecurityVSAvoidsetup complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple service-specific secure tunnels into a single unified secure tunnel. The relay device establishes one secure connection to the mobile communication network that can carry multiple services, eliminating the need for separate tunnels for each service and reducing overall system complexity while maintaining security

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The unified secure tunnel is designed to be universal, serving multiple services simultaneously. The tunnel establishment process creates a multi-functional communication channel that can handle different services without requiring separate tunnel setups, thereby reducing device complexity while preserving security requirements

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If a secure tunnel is established with each service separately, then security is maintained, but transmission efficiency decreases

Engineering Contradiction:
ImprovesecurityVSAvoidtransmission efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

By combining multiple service communications into a single unified secure tunnel, the patent eliminates redundant tunnel establishment and maintenance overhead. This merging approach reduces the total number of secure connections required, thereby improving transmission efficiency while maintaining the same security level through the unified tunnel

Inventive Principle:
Principle #5Merging (Combining)

3Device complexity

If security keys are derived without considering node handovers, then key derivation is simplified, but communication reliability breaks during handovers

Engineering Contradiction:
Improvekey derivation complexityVSAvoidcommunication continuity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent incorporates node identification information into the security key derivation process in advance. By including identifiers of potential relay nodes and network nodes in the key derivation algorithm, the system prepares for possible handovers beforehand, ensuring that security keys remain valid even when the relay device changes, thus maintaining communication reliability without adding significant complexity

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security key derivation process is modified to include dynamic parameters related to node identities and handover states. By changing the derivation parameters to account for different relay nodes and network nodes, the system ensures continuous secure communication during handovers while maintaining a relatively simple overall key derivation framework

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3535999B1Deriving a security key for relayed communication
Publication Date: 2022.06.01 KONINK KPN NV
  • EP3535999B1 patent drawingFigure 1~2
  • EP3535999B1 patent drawingFigure 3~4
  • EP3535999B1 patent drawingFigure 5

AI summary

A device (1) is configured to derive a first security key based on information relating to a first node (17), to request use of or to use a further device (9) as a relay to the mobile communication network and to determine whether the further device is connected to the first node and/or receive a message when another device, e.g. the first node, has determined that the further device is not connected to the first node. The device is further configured to, upon determining that the further device is not connected to the first node or upon receipt of the message, derive a second security key based on information relating to a second node (11) to which the further device is connected and transmit information via the further device, the information being encrypted using the second security key.