Remote Key Generation for Wireless Authentication Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In wireless telecommunications systems, particularly in distributed architectures, the network authentication key (OP key) is a vulnerable point for security, as its compromise can affect all users, and changing it requires reprogramming all user terminals, posing a significant security risk.
Innovation Solution
A method where the second authentication keys are generated by a remote key generation tool not connected to the network, with the first network authentication key stored outside the network, and the derived keys are stored on a data medium and transmitted to a database for distribution to authentication devices, ensuring the OP key is not stored on vulnerable HSS equipment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the network authentication key (OP key) is stored in centralized authentication equipment (HSS), then authentication operations can be performed, but the security of the network is compromised as the OP key becomes a vulnerable point
Solution Approach 1:
The invention extracts the master authentication key (OP key) from the authentication equipment (HSS) and stores it in a remote key generation tool that is not connected to the network. This removes the vulnerable point from the system while still enabling authentication operations through derived keys stored in the HSS.
Solution Approach 2:
The invention introduces a remote key generation tool as an intermediary between the OP key storage and the authentication equipment. This intermediary generates derived keys (OPc) that are stored in the HSS, allowing authentication to proceed without the OP key being present in the vulnerable authentication equipment.
2Reliability
If the OP key is changed after network deployment, then security can be updated, but all user terminal identification smart cards must be reprogrammed
Solution Approach 1:
The invention performs preliminary generation of derived keys (OPc) for each user terminal before network deployment or key changes. These derived keys are stored in the HSS in advance, so when the OP key needs to be changed, only the key generation tool needs to be updated, not all user terminals.
Solution Approach 2:
The invention segments the authentication key system into the master OP key (stored remotely and securely) and multiple derived OPc keys (stored in HSS and associated with specific terminals). This segmentation allows the OP key to be changed without affecting user terminals, as only the key generation process needs updating.
3Adaptability or versatility
If HSS equipment is distributed to remote locations for autonomous operation, then network coverage is improved, but securing the HSS equipment becomes more difficult
Solution Approach 1:
The invention extracts the OP key from distributed HSS equipment and stores it in a centralized remote key generation tool. This allows HSS equipment to be distributed for autonomous operation while eliminating the security risk of storing OP keys in multiple remote locations.
Solution Approach 2:
The invention creates copies of the OP key in derived forms (OPc) that are specific to each user terminal. These derived keys are stored in the distributed HSS equipment, allowing autonomous operation without requiring the master OP key to be present in each distributed location.
Data Source
Figure 1
Figure 2~3
AI summary
A method for processing authentication keys in a wireless telecommunications system (1) comprising user terminals (3) and a wireless telecommunications network (2) wherein: - determination by a remote key generation tool (8) of said authentication equipment and based on a first authentication key (OP) of the network, of a list (LOPc) of second authentication keys of the network (OPc), each determined for a user terminal of the network based on the first key and an authentication key (K) of said user terminal; - storage in a network authentication equipment of said second keys; - the user terminal verifies that a first part of the data transmitted by said authentication equipment indicates the second key associated with said terminal;