Enhanced Security Context Signaling for Wireless Session Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security protocols in UMTS and GERAN networks are vulnerable due to the infrequent updating of shared keys, which can lead to compromised security when keys are exposed, especially in insecure locations, and require network upgrades to implement session keys for enhanced security.
Innovation Solution
A method for establishing an enhanced security context between a remote station and a serving network by signaling support for a new security context with a count value, generating session keys, and receiving an authentication code to protect wireless communications, compatible with legacy networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If session keys are implemented to enhance security in exposed RNC locations, then security is improved, but network upgrade modifications are required
Solution Approach 1:
The patent introduces an information element as an intermediary carrier that transports security context identification between the remote station and serving network. This element enables enhanced security functionality without requiring core network upgrades, as it can be implemented at the radio access network level. The information element acts as a mediator that bridges legacy networks and enhanced security requirements.
Solution Approach 2:
The patent segments the security enhancement into modular components: an information element for signaling, session key generation at the RNC level, and optional authentication code verification. This segmentation allows incremental deployment where only RNCs needing enhanced security implement the full functionality, while legacy RNCs continue operating with existing security mechanisms.
2Reliability
If AKA authentication is run frequently to change compromised keys, then security is improved, but significant overhead is required
Solution Approach 1:
The patent implements periodic key derivation based on session counters rather than requiring frequent full AKA authentication cycles. The serving network and remote station derive new session keys from existing master keys using counter values that increment with each session, providing regular key rotation without the overhead of complete authentication procedures.
Solution Approach 2:
The patent performs preliminary key derivation by establishing master keys through AKA authentication once, then pre-configuring the mechanism for deriving multiple session keys from these master keys. This preliminary action eliminates the need to repeat the full AKA authentication process for each key change, reducing overhead while maintaining security.
3Reliability
If both CK and IK keys are compromised in GERAN, then security is severely weakened, but detecting key compromise is difficult
Solution Approach 1:
The patent implements feedback mechanisms through authentication codes that allow the remote station to verify whether derived session keys are valid. If keys have been compromised or are incorrect, the authentication code verification will fail, providing immediate feedback about key validity. This enables detection of key compromise without requiring complex monitoring systems.
Data Source
AI summary
Disclosed is a method for establishing an enhanced security context between a remote station and a serving network. In the method, the remote station forwards a first message to the serving network, wherein the first message includes an information element signaling that the remote station supports an enhanced security context. The remote station generates at least one session key, in accordance with the enhanced security context, using the information element. The remote station receives, in response to the first message, a second message having an indication that the serving network supports the enhanced security context. The remote station, in response to the second message, has wireless communications protected by the at least one session key.


