Enhanced Security Context Signaling for Wireless Session Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security protocols in UMTS and GERAN networks are vulnerable due to the infrequent updating of shared keys, which can lead to compromised security when keys are exposed, especially in insecure locations, and require network upgrades to implement session keys for enhanced security.

Innovation Solution

A method for establishing an enhanced security context between a remote station and a serving network by signaling support for a new security context with a count value, generating session keys, and receiving an authentication code to protect wireless communications, compatible with legacy networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If session keys are implemented to enhance security in exposed RNC locations, then security is improved, but network upgrade modifications are required

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork upgrade modifications
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an information element as an intermediary carrier that transports security context identification between the remote station and serving network. This element enables enhanced security functionality without requiring core network upgrades, as it can be implemented at the radio access network level. The information element acts as a mediator that bridges legacy networks and enhanced security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the security enhancement into modular components: an information element for signaling, session key generation at the RNC level, and optional authentication code verification. This segmentation allows incremental deployment where only RNCs needing enhanced security implement the full functionality, while legacy RNCs continue operating with existing security mechanisms.

Inventive Principle:
Principle #1Segmentation

2Reliability

If AKA authentication is run frequently to change compromised keys, then security is improved, but significant overhead is required

Engineering Contradiction:
ImprovesecurityVSAvoidoverhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements periodic key derivation based on session counters rather than requiring frequent full AKA authentication cycles. The serving network and remote station derive new session keys from existing master keys using counter values that increment with each session, providing regular key rotation without the overhead of complete authentication procedures.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent performs preliminary key derivation by establishing master keys through AKA authentication once, then pre-configuring the mechanism for deriving multiple session keys from these master keys. This preliminary action eliminates the need to repeat the full AKA authentication process for each key change, reducing overhead while maintaining security.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If both CK and IK keys are compromised in GERAN, then security is severely weakened, but detecting key compromise is difficult

Engineering Contradiction:
Improvesecurity vulnerabilityVSAvoidkey compromise detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements feedback mechanisms through authentication codes that allow the remote station to verify whether derived session keys are valid. If keys have been compromised or are incorrect, the authentication code verification will fail, providing immediate feedback about key validity. This enables detection of key compromise without requiring complex monitoring systems.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9197669B2Apparatus and method for signaling enhanced security context for session encryption and integrity keys
Publication Date: 2015.11.24 QUALCOMM INC
  • US9197669B2 patent drawing
  • US9197669B2 patent drawing
  • US9197669B2 patent drawing

AI summary

Disclosed is a method for establishing an enhanced security context between a remote station and a serving network. In the method, the remote station forwards a first message to the serving network, wherein the first message includes an information element signaling that the remote station supports an enhanced security context. The remote station generates at least one session key, in accordance with the enhanced security context, using the information element. The remote station receives, in response to the first message, a second message having an indication that the serving network supports the enhanced security context. The remote station, in response to the second message, has wireless communications protected by the at least one session key.