Small Data Security Key Derivation for Wireless Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless communication systems face challenges in ensuring the security of small data communications, particularly due to significant control signaling overhead and mobility of wireless devices, which complicates maintaining confidentiality and integrity protection.

Innovation Solution

The method involves triggering wireless devices to derive new or updated security keys based on horizontal derivation of a base security key, using control signaling from mobility management network equipment, incorporating a freshness parameter to ensure secure small data communications despite device mobility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of energy

If small data communication over user plane is used, then control signaling overhead is reduced, but security protection becomes challenging

Engineering Contradiction:
Improvecontrol signaling overheadVSAvoidsecurity protection
Core Design Contradiction:
Loss of energyVSReliability

Solution Approach 1:

The patent implements dynamic security key derivation where the SDT security key is updated based on the AMF identity and a counter value. This dynamic approach ensures that security keys change adaptively with network conditions and device mobility, maintaining security protection while enabling efficient user plane small data communication without frequent connection setups.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes security key parameters by deriving the SDT security key from multiple inputs including the base security key, AMF identity, and counter value. This parameter-based key derivation allows the system to maintain strong security protection while operating in the optimized user plane mode, resolving the contradiction between reduced signaling overhead and maintained security.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If horizontal derivation of base security key is performed due to device mobility, then security is maintained, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service horizontal key derivation where the wireless device autonomously derives the SDT security key using the base security key, AMF identity, and counter value stored in its security context. This self-service approach maintains security during device mobility without requiring complex network-side key management, thereby limiting the increase in device complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary setup of the security context including the base security key and counter value during initial connection establishment. This preliminary action enables subsequent horizontal key derivation to proceed efficiently during mobility events, maintaining security while avoiding repeated complex key setup procedures that would increase device complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12041441B2Small data communication security
Publication Date: 2024.07.16 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US12041441B2 patent drawing
  • US12041441B2 patent drawing
  • US12041441B2 patent drawing

AI summary

Methods and apparatus for small data communications over a user plane in a wireless communication network. A method performed by a wireless device comprises receiving, from mobility management network equipment (e.g., implementing an AMF), control signaling indicating that the wireless device is to horizontally derive a base security key and/or that the wireless device is to derive a small data transfer, SDT, security key from the base security key. The base security key may be included in a non-access stratum, NAS, security context at the wireless device and at the mobility management network equipment. The method may further comprise, responsive to receiving the control signaling, deriving the SDT security key from the base security key and a freshness parameter.