Satellite Key Establishment for 256-Bit Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a growing need for enhanced security protocols in 3G mobile satellite systems, particularly those based on extended key lengths to combat increasing security risks, as existing terrestrial 3G protocols rely on 128-bit keys which are insufficient for high-security applications.

Innovation Solution

The implementation of a method and apparatus that perform key establishment functions, including determining first and second encryption keys for data transmission and authentication, using a key indicator and algorithms to enhance session data security, enabling encryption of packet data protocol context activation processes and session data transmission with improved security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If extended key lengths (e.g., 256 bits) are used for encryption, then security strength is improved, but device complexity and processing overhead increase

Engineering Contradiction:
Improvesecurity strengthVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by transitioning from 128-bit to 256-bit key lengths in the encryption algorithm. This fundamental parameter change in the cryptographic system provides enhanced security strength while maintaining compatibility with existing 3G protocol frameworks, thereby managing device complexity through standardized implementation

Inventive Principle:
Principle #35Parameter changes

2Reliability

If extended key lengths (e.g., 256 bits) are used for encryption, then security strength is improved, but processing speed decreases

Engineering Contradiction:
Improvesecurity strengthVSAvoidprocessing speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent implements preliminary action by performing key derivation and security parameter negotiation during the initial connection establishment phase. This allows the enhanced 256-bit encryption to be prepared in advance, minimizing the impact on processing speed during actual data transmission operations

Inventive Principle:
Principle #10Preliminary action

3Reliability

If 256-bit encryption keys are implemented, then security against threats is improved, but compatibility with existing terrestrial 3G protocols deteriorates

Engineering Contradiction:
Improvesecurity against threatsVSAvoidcompatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies segmentation by separating the security enhancement into distinct layers: maintaining compatibility with existing terrestrial 3G non-access stratum protocols while implementing 256-bit encryption in the access stratum specific to satellite communications. This layered approach preserves interoperability while enhancing security

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by applying enhanced 256-bit encryption specifically to satellite communication channels where security risks are highest, while maintaining standard 128-bit protocols in terrestrial network segments. This localized enhancement provides improved security where needed without compromising overall system compatibility

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP2992696B1Data encryption protocols for mobile satellite communications
Publication Date: 2018.10.03 HUGHES NETWORK SYST
  • EP2992696B1 patent drawingFigure 1A
  • EP2992696B1 patent drawingFigure 1B
  • EP2992696B1 patent drawingFigure 2A

AI summary

An approach for improved security protocols in a mobile satellite system is provided. A remote terminal performs a key establishment function, including determination of a first encryption key for encrypting data for transmission over the satellite communications channels, and determination of an authentication key for authenticating entities communicating over the communications channels. The remote terminal receives a security mode command including a key indicator, and determines a second encryption key for enhanced session data security over communications channels. The second encryption key is determined based on the key indicator and a key generation algorithm. The remote terminal further determines a key indicator response and transmits a security mode complete command including the key indicator response to a satellite base station subsystem (SBSS). The key indicator response is constructed for the SBSS to determine the second encryption key based on the key indicator response and a key generation algorithm.