Secure Element Authentication Key Derivation via SRT
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing authentication processes in telecommunications are vulnerable to passive eavesdropping due to the sensitivity of the pre-shared secret key K, which can be compromised, allowing malicious parties to intercept and decipher communications.
Innovation Solution
The method involves generating an anchor key (KSEAF_SRT) by deriving the long-term key K using a secure registration token (SRT) sent by the terminal, encrypted with the AUSF/UDM/ARPF public key and SUPI in the SUCI, to enhance security and prevent eavesdropping.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the long-term key K is used for authentication, then authentication can be performed, but the system becomes vulnerable to passive eavesdropping and key compromise
Solution Approach 1:
The authentication system is segmented into two independent key components: the long-term key K stored in the USIM and the ephemeral key pair (public key PEK, private key SEK) stored in the secure element. This segmentation ensures that compromising one component does not expose the other, thereby preventing passive eavesdropping while maintaining authentication functionality.
Solution Approach 2:
The secure element generates and stores the ephemeral key pair (PEK, SEK) in advance, before any authentication process begins. This preliminary action ensures that the private key SEK never leaves the secure element, preventing key compromise while enabling secure authentication through the public key PEK.
2Reliability
If the long-term key K is stored in the USIM, then authentication is enabled, but the key may be compromised by manufacturers or attackers
Solution Approach 1:
The authentication credentials are segmented between two separate storage locations: the long-term key K remains in the USIM while the ephemeral private key SEK is stored in the secure element. This segmentation prevents single-point compromise, as attackers would need to compromise both storage locations simultaneously.
Solution Approach 2:
The public key PEK acts as an intermediary that enables authentication without exposing the private key SEK. The PEK can be freely transmitted and stored, serving as a safe mediator that allows the secure element to prove its identity without revealing the sensitive private key that would otherwise be vulnerable to compromise.
3Object-affected harmful factors
If a secure registration token SRT is introduced for anchor key derivation, then security against eavesdropping is improved, but the system complexity increases
Solution Approach 1:
The secure registration token SRT is generated and stored in the secure element during the initial provisioning phase, before the device is deployed. This preliminary action eliminates the need for complex runtime generation and distribution of SRT, simplifying the authentication process while maintaining security against eavesdropping.
Solution Approach 2:
The secure element autonomously generates and manages the secure registration token SRT and ephemeral key pair (PEK, SEK) without external intervention. This self-service capability reduces system complexity by eliminating the need for secure key distribution infrastructure, as the secure element performs all cryptographic operations internally using its built-in capabilities.
Data Source
AI summary
A system and method for authentication of a secure element cooperating with a Mobile Equipment forming a terminal in a telecommunication network is provided. The telecommunication network comprises a SEAF and a AUSF/UDM/ARPF. The method includes generating an anchor key (KSEAF_SRT) for the communication between the terminal and the SEAF according to 3GPP TS 33.501, wherein the anchor key (KSEAF_SRT) is indirectly derived from a key (KSRT) obtained by deriving from the long-term key K and a secure registration token SRT sent by the terminal to the AUSF/UDM/ARPF and concealed with the AUSF/UDM/ARPF public key along with its SUPI in the SUCI. Other embodiments are disclosed.


