Secure Element Key Derivation for UWB Ranging Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication systems face security challenges in ranging sessions between user equipment (UE) and other devices, as the secure ranging key is at risk of exposure due to its storage in less secure ultra-wideband (UWB) modules.
Innovation Solution
The secure ranging key is maintained in a secure element (SE) and used to derive other keys, which are then fetched by the UWB module, thereby reducing the risk of key exposure by requiring more keys to be stolen from the less secure UWB module.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the secure ranging key is stored in the ultra-wideband (UWB) module, then the ranging session can be established, but the security is compromised due to the risk of key exposure
Solution Approach 1:
The patent segments the key management functions by separating the secure ranging key storage from the UWB module. The secure element (SE) maintains the secure ranging key, while the UWB module only stores derived keys. This segmentation ensures that the most sensitive key material remains in the most secure location, reducing the attack surface while still enabling UWB ranging functionality.
Solution Approach 2:
The patent introduces an intermediary key derivation mechanism where the secure element derives additional keys from the secure ranging key and provides them to the UWB module. This intermediary approach allows the UWB module to function without directly accessing the master secure ranging key, thereby maintaining security while enabling operation.
2Reliability
If the secure ranging key is stored in a secure element, then security is improved, but the device complexity increases due to multiple key management components
Solution Approach 1:
The patent merges the key derivation functionality into the secure element, which already exists in modern mobile devices for other security purposes. By combining the secure ranging key management with the existing secure element infrastructure, the patent avoids adding a completely separate key management system, thereby reducing overall device complexity while maintaining enhanced security.
Data Source
AI summary
Certain aspects of the present disclosure provide techniques for secure digital key derivation for a ranging session between a first device (e.g., a user equipment (UE)) and a second device (e.g., a vehicle). According to certain aspects, a first device maintains a secure ranging in a secure element (SE) at the first device. The first device further fetches, from the SE, one or more other keys derived from the secure ranging key. The first device further uses the one or more other keys to secure a ranging session between the first device and a second device.


