Secondary Node Key Generation Using Counter Lists

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication networks face challenges in securely providing keys for communication between user equipment (UE) and secondary nodes (SNs) while minimizing signaling and bookkeeping overhead.

Innovation Solution

A method involving obtaining secondary node counter lists from a master node, generating a secondary node key based on these lists and an indication of a secondary node, and using this key for access to the secondary node.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single key is provided to the network node and UE for communication sessions, then key management is simplified, but key reuse occurs when the UE reconnects to the same network node, creating security hazards

Engineering Contradiction:
Improvekey management complexityVSAvoidcommunication security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the key management system by introducing counter lists that are specific to each network node. Instead of using a single shared key, the system divides key derivation into node-specific segments through counter lists, where each network node has its own counter list that the UE uses to generate unique keys for that specific node, preventing key reuse across different nodes

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies preliminary action by providing the UE with counter lists from the network before actual communication sessions occur. These counter lists are prepared in advance and stored in the UE, enabling the UE to generate appropriate keys for future connections to specific network nodes without requiring real-time key provisioning, thus preventing key reuse while maintaining simplicity

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple SNs are provided with a list of keys to use, then key reuse is avoided, but signaling overhead and bookkeeping complexity increase

Engineering Contradiction:
Improvecommunication securityVSAvoidsignaling and bookkeeping overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the UE to autonomously generate keys for accessing secondary nodes using the counter lists it已获得 from the master node. The UE independently selects the appropriate counter list based on the target SN and generates the corresponding key without requiring the SN to maintain key lists or perform complex key management operations, thus avoiding key reuse while minimizing signaling overhead

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent extracts the key management burden from the secondary nodes and centralizes it in the UE. By providing counter lists to the UE and enabling it to generate keys locally, the system removes the need for SNs to store and manage multiple keys, eliminating the bookkeeping overhead that would otherwise be required at the SN side while still preventing key reuse

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20250056220A1Key provision
Publication Date: 2025.02.13 NOKIA TECHNOLOGIES OY
  • US20250056220A1 patent drawing
  • US20250056220A1 patent drawing
  • US20250056220A1 patent drawing

AI summary

Methods, apparatus and systems for provision of keys in a communication network are disclosed.