Stateless Access Stratum Security for CIoT
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cellular Internet of Things (CIoT) devices face high overhead and latency in establishing UE Contexts, leading to increased energy consumption and vulnerabilities such as denial of service attacks due to the need for frequent security context establishment and mobility management in LTE networks.
Innovation Solution
Implementing a stateless access stratum security scheme where a CloT Serving Gateway Node (C-SGN) generates and provisions keys to RAN nodes and cellular devices, allowing for integrity protection and encryption of small data messages without maintaining a per-device access stratum security context, using a Master Access Stratum Key (MASK), Base Station Access Stratum Key (BASK), and Device Access Stratum Key (DASK) derived through key derivation functions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If stateful security context management is implemented in LTE networks for CIoT devices, then access stratum security is maintained, but overhead and latency increase leading to higher energy consumption
Solution Approach 1:
The patent extracts the security context management from the RAN node by introducing a separate security management entity (SME) in the core network. This separation allows the RAN node to operate statelessly while the SME maintains security contexts, reducing overhead and energy consumption at the RAN node while maintaining security functionality.
Solution Approach 2:
The patent introduces a security management entity (SME) as an intermediary between the RAN node and the cellular device. The SME handles security context establishment, maintenance, and key management, allowing the RAN node to authenticate devices without maintaining stateful security contexts, thus reducing overhead and energy consumption.
2Reliability
If frequent security context establishment and mobility management are performed in LTE networks, then security is maintained, but vulnerabilities such as denial of service attacks increase
Solution Approach 1:
The patent extracts security context management from the RAN node to a dedicated security management entity in the core network. This allows the RAN node to operate statelessly, reducing its attack surface and vulnerability to denial of service attacks while maintaining security functionality through the SME.
Solution Approach 2:
The patent implements preliminary security context establishment at the core network level before devices need to access the network. Security contexts are pre-configured and managed by the SME, allowing rapid authentication without frequent stateful context establishment at the RAN node, reducing vulnerability to timing-based attacks.
3Reliability
If stateful security context management is implemented, then access stratum security is maintained, but overhead and latency increase
Solution Approach 1:
The patent extracts security context management from the RAN node to a separate security management entity in the core network. This allows the RAN node to operate statelessly with reduced processing overhead, while the SME handles security context operations, reducing latency in security operations at the RAN node.
Solution Approach 2:
The patent implements preliminary security context establishment and key derivation at the core network level before devices need to access the network. Security contexts are pre-configured and cached by the SME, enabling rapid authentication and reducing latency during actual device access operations.
4Reliability
If per-device access stratum security context is maintained at RAN nodes, then security is ensured, but device complexity and overhead increase
Solution Approach 1:
The patent extracts security context management functionality from the RAN node to a dedicated security management entity in the core network. This separation reduces RAN node complexity by removing the need to maintain stateful security contexts for multiple devices, while the SME handles all security context operations centrally.
Solution Approach 2:
The patent implements a universal security management entity that serves multiple RAN nodes and devices through centralized security context management. The SME provides security services to multiple RAN nodes without requiring each RAN node to maintain individual stateful contexts, reducing overall system complexity while maintaining security.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Aspects of security schemes (e.g., integrity protection, encryption, or both) are described. A measure of access stratum security can be realized without overhead associated with establishing and/or maintaining the per-cellular-device access stratum security context at a Cellular Internet of Things (CIoT) base station (C-BS). A gateway (e.g., a CIoT Serving Gateway Node (C-SGN)) may derive a first key. The first key may be only known to the C-SGN. The C-SGN may derive a second key from the first key and a parameter unique to the C-BS. The C-SGN may also derive a third key from the second key and an identity of a cellular device. The C-SGN may send the second and third keys to the C-BS and cellular device, respectively. Small data messages encrypted and/or integrity protected by the cellular device may be decrypted and/or verified by the C-BS.