Shared PLMN Public Key for RRC Message Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication systems lack secure encryption for RRC connection setup messages, leading to potential exposure of confidential information, and existing solutions increase signaling overhead and require frequent key changes when a user equipment (UE) moves between access nodes.
Innovation Solution
Implementing a shared public key across access nodes and cells within a public land mobile network (PLMN) to encrypt RRC connection setup messages, allowing the UE to determine if an access node supports decryption and using a PLMN public key for encryption, with decryption handled either locally by trusted access nodes or a public key decryption service.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a public key is used for each access node to encrypt RRC connection setup messages, then security is improved, but signaling overhead increases and key management becomes complex when UE moves between access nodes
Solution Approach 1:
The patent merges the public keys of multiple access nodes into a single shared public key that is valid across the entire PLMN. This allows the UE to use one public key for encrypting RRC connection setup messages regardless of which access node it connects to, eliminating the need for separate key management per access node while maintaining security.
Solution Approach 2:
The shared public key serves multiple access nodes simultaneously, making it universal across the PLMN. This universal key enables the UE to establish secure connections with any access node in the network without requiring access-node-specific keys, thereby reducing key management complexity and signaling overhead during mobility events.
2Speed
If access nodes store private keys locally for decryption, then decryption speed is improved, but security risk increases if access nodes are compromised
Solution Approach 1:
The patent introduces a dedicated key management entity as an intermediary between the UE and access nodes. This entity securely stores the private key and performs decryption operations on behalf of access nodes. The access nodes forward encrypted messages to this intermediary for decryption, which then returns the decrypted messages. This mediator approach maintains fast decryption while eliminating the security risk of private keys being stored in potentially compromised access nodes.
Solution Approach 2:
The patent extracts the private key storage function from the access nodes and places it in a dedicated key management entity. This separation removes the security vulnerability of having private keys distributed across multiple access nodes, while the key management entity provides centralized secure storage and decryption services.
Data Source
Figure 1~2
Figure 3
Figure 4~5
AI summary
An apparatus comprising means for: determining a shared public key shared by a plurality of access nodes and/or cells in a public land mobile network; and providing at least one message to at least one of the plurality of access nodes and/or cells, wherein at least part of the at least one message is encrypted based on the shared public key.