Serving Network PFS Control via Home Network Indicator
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless network security procedures, specifically in the 3GPP framework, do not allow the home network to control the employment of perfect forward security (PFS) between user equipment and serving networks, leading to issues such as lack of awareness of session keys and suboptimal key management during Legal Interception scenarios.
Innovation Solution
A method where the serving network selectively employs PFS based on an indication from the home network, allowing the home network to decide on PFS usage and ensuring both networks have separate keys with PFS properties, generated through a Diffie-Hellman key exchange procedure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the serving network autonomously decides to employ PFS based on user equipment capabilities and serving network preferences, then the security quality between user equipment and serving network is improved, but the home network loses control over PFS employment and becomes unaware of session keys
Solution Approach 1:
The patent introduces a PFS indicator as an intermediary mechanism that allows the home network to communicate its PFS employment preference to the serving network. This indicator acts as a mediator that carries the home network's authorization decision, enabling the serving network to autonomously execute PFS while respecting home network control preferences, thus resolving the contradiction between security quality improvement and home network control.
2Reliability
If the serving network and user equipment share a secret key generated through Diffie-Hellman procedure, then perfect forward security is achieved, but the home network can no longer derive session keys and Legal Interception becomes problematic
Solution Approach 1:
The patent segments the key management process into two distinct paths: (1) The Diffie-Hellman procedure between serving network and user equipment generates a secret key for their direct communication, achieving PFS; (2) A separate key derivation mechanism allows the home network to independently derive session keys from authentication vectors. This segmentation resolves the contradiction by allowing PFS while preserving home network key awareness for Legal Interception purposes.
3Loss of information
If standard authentication procedures are used, then the home network can derive session keys for Legal Interception, but the security quality is suboptimal compared to Diffie-Hellman based PFS
Solution Approach 1:
The patent merges two previously separate mechanisms: (1) The Diffie-Hellman key exchange procedure that provides superior security and PFS properties; (2) The home network's key derivation capability from authentication vectors. By combining these mechanisms and coordinating them through the PFS indicator, the system achieves both high security quality and home network key awareness, resolving the contradiction between security quality and key derivation capability.
Data Source
AI summary
A method for a serving network to selectively employ perfect forward security (PFS) based on an indication from a home network is described. The method includes receiving, by the serving network, a PFS indicator from the home network; determining, by the serving network, whether the PFS indicator indicates that the home network has instructed the serving network to employ PFS for communications with a piece of user equipment; and performing, by the serving network, a PFS procedure with the piece of user equipment in response to determining that the PFS indicator indicates that the home network has instructed the serving network to employ PFS for communications with the piece of user equipment.


