Secure Policy Messaging with PCF Key Derivation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless networks, the provision of UE route selection policy (URSP) information to user equipment (UE) is vulnerable to security threats due to the lack of integrity and encryption protection, leading to potential unauthorized modifications and compromised quality of service.

Innovation Solution

A PCF device generates an integrity key and an encryption key based on a PCF device key and identifier, encrypts policy information, and sends a UE policy message with integrity data and the identifier, allowing the UE to validate and decrypt the information securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If policy information is transmitted without integrity and encryption protection, then the transmission process is simple and fast, but the security of the policy information is compromised and unauthorized modifications may occur

Engineering Contradiction:
Improvesecurity of policy informationVSAvoidcomplexity of policy messaging
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by generating integrity keys and encryption keys before transmitting policy information. The PCF device generates an integrity key derivation and encryption key derivation in advance, then uses these keys to protect the policy information before transmission. This ensures security measures are in place before the actual data transfer occurs, preventing security breaches rather than reacting to them.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses an intermediary approach by introducing key derivation mechanisms as intermediaries between the policy information and its transmission. The integrity key derivation and encryption key derivation act as intermediaries that transform the original policy information into a protected form. These intermediaries add security layers without directly modifying the core policy data, maintaining a clear separation between the original information and its protected representation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If integrity key and encryption key are generated and used for protecting policy information, then the security and confidentiality are enhanced, but the processing time and computational overhead increase

Engineering Contradiction:
Improveintegrity and confidentiality of URSP informationVSAvoidtime for key generation and encryption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by performing key derivations before the actual policy information transmission. The integrity key derivation and encryption key derivation are executed in advance, allowing the system to prepare security credentials beforehand. This reduces the time penalty during actual policy messaging, as the computational heavy lifting occurs before the time-sensitive transmission phase.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-service by enabling the UE to independently derive the same integrity key and encryption key using its own context and the received parameters. Instead of the network providing pre-computed keys, both the PCF and UE autonomously generate identical keys through a standardized derivation process. This distributes the computational burden and eliminates the need for secure key distribution channels, reducing overall system overhead.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12368599B2Systems and methods for secure policy messaging
Publication Date: 2025.07.22 VERIZON PATENT & LICENSING INC
  • US12368599B2 patent drawing
  • US12368599B2 patent drawing
  • US12368599B2 patent drawing

AI summary

In some implementations, a policy control function (PCF) device may receive a PCF device key uniquely associated with a user equipment (UE). The PCF device may generate an integrity key and an encryption key based on the PCF device key and an identifier of the PCF device. The PCF device may generate, based on the integrity key, integrity data associated with policy information related to the UE. The PCF device may encrypt, based on the encryption key, the policy information to generate encrypted policy information. The PCF device may send, for the UE, a UE policy message indicating the integrity data, the encrypted policy information, and the identifier of the PCF device.