Remote Key Generation for Wireless Authentication Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless telecommunications systems, particularly in distributed architectures, the network authentication key (OP key) is a vulnerable point for security, as its compromise can affect all users, and changing it requires reprogramming all user terminals, posing a significant security risk.

Innovation Solution

A method where the second authentication keys are generated by a remote key generation tool not connected to the network, with the first network authentication key stored outside the network, and the derived keys are stored on a data medium and transmitted to a database for distribution to authentication devices, ensuring the OP key is not stored on vulnerable HSS equipment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the network authentication key (OP key) is stored in centralized authentication equipment (HSS), then authentication operations can be performed, but the security of the network is compromised as the OP key becomes a vulnerable point

Engineering Contradiction:
Improveauthentication operationVSAvoidsecurity vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The invention extracts the master authentication key (OP key) from the authentication equipment (HSS) and stores it in a remote key generation tool that is not connected to the network. This removes the vulnerable point from the system while still enabling authentication operations through derived keys stored in the HSS.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The invention introduces a remote key generation tool as an intermediary between the OP key storage and the authentication equipment. This intermediary generates derived keys (OPc) that are stored in the HSS, allowing authentication to proceed without the OP key being present in the vulnerable authentication equipment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the OP key is changed after network deployment, then security can be updated, but all user terminal identification smart cards must be reprogrammed

Engineering Contradiction:
Improvesecurity updateVSAvoidreprogramming operation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The invention performs preliminary generation of derived keys (OPc) for each user terminal before network deployment or key changes. These derived keys are stored in the HSS in advance, so when the OP key needs to be changed, only the key generation tool needs to be updated, not all user terminals.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention segments the authentication key system into the master OP key (stored remotely and securely) and multiple derived OPc keys (stored in HSS and associated with specific terminals). This segmentation allows the OP key to be changed without affecting user terminals, as only the key generation process needs updating.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If HSS equipment is distributed to remote locations for autonomous operation, then network coverage is improved, but securing the HSS equipment becomes more difficult

Engineering Contradiction:
Improveautonomous operationVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The invention extracts the OP key from distributed HSS equipment and stores it in a centralized remote key generation tool. This allows HSS equipment to be distributed for autonomous operation while eliminating the security risk of storing OP keys in multiple remote locations.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The invention creates copies of the OP key in derived forms (OPc) that are specific to each user terminal. These derived keys are stored in the distributed HSS equipment, allowing autonomous operation without requiring the master OP key to be present in each distributed location.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP2846513B1Method for processing authentication keys in a wireless telecommunication system, and related telecommunication system
Publication Date: 2016.02.03 THALES SA
  • EP2846513B1 patent drawingFigure 1
  • EP2846513B1 patent drawingFigure 2~3
  • EP2846513B1 patent drawing

AI summary

A method for processing authentication keys in a wireless telecommunications system (1) comprising user terminals (3) and a wireless telecommunications network (2) wherein: - determination by a remote key generation tool (8) of said authentication equipment and based on a first authentication key (OP) of the network, of a list (LOPc) of second authentication keys of the network (OPc), each determined for a user terminal of the network based on the first key and an authentication key (K) of said user terminal; - storage in a network authentication equipment of said second keys; - the user terminal verifies that a first part of the data transmitted by said authentication equipment indicates the second key associated with said terminal;