Shared PLMN Public Key for RRC Message Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication systems lack secure encryption for RRC connection setup messages, leading to potential exposure of confidential information, and existing solutions increase signaling overhead and require frequent key changes when a user equipment (UE) moves between access nodes.

Innovation Solution

Implementing a shared public key across access nodes and cells within a public land mobile network (PLMN) to encrypt RRC connection setup messages, allowing the UE to determine if an access node supports decryption and using a PLMN public key for encryption, with decryption handled either locally by trusted access nodes or a public key decryption service.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a public key is used for each access node to encrypt RRC connection setup messages, then security is improved, but signaling overhead increases and key management becomes complex when UE moves between access nodes

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the public keys of multiple access nodes into a single shared public key that is valid across the entire PLMN. This allows the UE to use one public key for encrypting RRC connection setup messages regardless of which access node it connects to, eliminating the need for separate key management per access node while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The shared public key serves multiple access nodes simultaneously, making it universal across the PLMN. This universal key enables the UE to establish secure connections with any access node in the network without requiring access-node-specific keys, thereby reducing key management complexity and signaling overhead during mobility events.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Speed

If access nodes store private keys locally for decryption, then decryption speed is improved, but security risk increases if access nodes are compromised

Engineering Contradiction:
Improvedecryption speedVSAvoidsecurity risk
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a dedicated key management entity as an intermediary between the UE and access nodes. This entity securely stores the private key and performs decryption operations on behalf of access nodes. The access nodes forward encrypted messages to this intermediary for decryption, which then returns the decrypted messages. This mediator approach maintains fast decryption while eliminating the security risk of private keys being stored in potentially compromised access nodes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the private key storage function from the access nodes and places it in a dedicated key management entity. This separation removes the security vulnerability of having private keys distributed across multiple access nodes, while the key management entity provides centralized secure storage and decryption services.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3902299B1Apparatus, method, and computer program
Publication Date: 2024.06.19 NOKIA TECHNOLOGIES OY
  • EP3902299B1 patent drawingFigure 1~2
  • EP3902299B1 patent drawingFigure 3
  • EP3902299B1 patent drawingFigure 4~5

AI summary

An apparatus comprising means for: determining a shared public key shared by a plurality of access nodes and/or cells in a public land mobile network; and providing at least one message to at least one of the plurality of access nodes and/or cells, wherein at least part of the at least one message is encrypted based on the shared public key.