Roaming Security Key Mediation for Untrusted Visited Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile communication systems lack an architecture that enables secure communication for terminals roaming outside their home network when the home network does not trust the visited network, as they are designed under the assumption that the home network trusts the visited network.
Innovation Solution
Introduce a network node apparatus with a reception unit, control unit, and transmission unit to manage security algorithms and keys, ensuring secure communication by concealing and integrity-protecting messages between the terminal and the home network's UPF, even when the home network does not trust the visited network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the home network trusts the visited network during roaming, then the communication architecture is simpler and easier to operate, but security reliability deteriorates when the home network should not trust the visited network
Solution Approach 1:
The patent introduces a security management function as an intermediary between the home network and visited network. This function receives security capability information from the terminal, selects appropriate security algorithms, and manages key distribution. By inserting this intermediary layer, the system achieves secure communication without requiring direct trust between home and visited networks, thus resolving the contradiction between operational simplicity and security reliability.
2Reliability
If security algorithms and keys are managed centrally in the home network, then security reliability is improved, but device complexity increases due to additional security management functions
Solution Approach 1:
The patent integrates multiple security management functions into a single network node apparatus that can operate in both roaming and non-roaming scenarios. The apparatus performs security capability information reception, security algorithm selection, and key management functions. By designing a multi-functional device, the patent achieves centralized security management without proportionally increasing overall system complexity, as the same apparatus handles different functions based on operational context.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A network node apparatus includes: a reception unit configured to receive, from a first network node apparatus that handles authentication control or service provisioning control, terminal security capability information and a key; a control unit configured to select a security algorithm used for secure communication between a terminal and a second network node apparatus, and to derive a concealment key and an integrity protection key; and a transmission unit configured to transmit the security algorithm, the concealment key, and the integrity protection key to the second network node apparatus, and to transmit the security algorithm to the terminal.