Unified Authentication Key Management for Heterogeneous Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In heterogeneous home networks, the different authentication and key management processes for various MAC layer technologies lead to resource wastage during the authentication process, as each technology requires separate authentication and key negotiation procedures, resulting in inefficient security management.

Innovation Solution

A unified authentication and key management method that generates a Network Key (NK) for network equipment, allowing it to perform a single authentication protocol interaction to calculate a Basic Session Key (BSK), which is then used to derive link Encryption Keys (EKs) for multiple MAC and PHY layers, ensuring seamless encryption and decryption across various access technologies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate authentication and key negotiation processes are performed for each MAC layer technology, then security authentication can be completed for each interface, but calculation resources are wasted due to redundant authentication operations

Engineering Contradiction:
Improvesecurity authenticationVSAvoidcalculation resource
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent merges multiple separate authentication and key negotiation processes into a single unified authentication process. The authentication management module performs one authentication operation that generates a master key, from which all necessary link encryption keys for different MAC layer technologies (PLC, MoCA, WiFi) are derived through key derivation functions, eliminating redundant authentication calculations while maintaining security for each interface

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal authentication mechanism where a single authentication process produces a master key that serves multiple functions. This master key can derive link encryption keys for various MAC layer technologies through key derivation, making the authentication system multi-functional and applicable to heterogeneous network interfaces without requiring separate authentication for each

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If different authentication and key management methods are applied for various MAC layer technologies, then each technology can use its specified authentication process, but the authentication process becomes complex and requires multiple separate procedures

Engineering Contradiction:
Improveauthentication processVSAvoidauthentication process
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the key management function from the authentication function. The authentication management module handles authentication and generates a master key, while separate key derivation modules derive specific link encryption keys for each MAC layer technology (PLC, MoCA, WiFi) from this master key. This segmentation allows a single authentication process to support multiple technologies without increasing overall system complexity

Inventive Principle:
Principle #1Segmentation

3Reliability

If multiple authentication protocol interactions are performed for multiple MAC layer technologies, then security can be ensured for each link, but the authentication time increases

Engineering Contradiction:
Improvelink securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary authentication at the authentication management module before data transmission begins. The master key is generated in advance through a single authentication protocol interaction, and all link encryption keys for different MAC layer technologies are derived from this pre-generated master key. This preliminary action eliminates the need for repeated authentication interactions during subsequent data transmission across multiple interfaces

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2863578B1Network device and authentication thereof and key management method
Publication Date: 2019.10.30 ZTE CORP
  • EP2863578B1 patent drawingFigure 1~2
  • EP2863578B1 patent drawingFigure 3
  • EP2863578B1 patent drawingFigure 4~5

AI summary

Provided is a network equipment and an authentication and key management method for the same. The network equipment generates a Network Key (NK); the network equipment performs authentication protocol interaction with opposite communication equipment, and calculates a Basic Session Key (BSK) according to parameters for the authentication protocol interaction and the NK; and the network equipment calculates link Encryption Keys (EKs) used respectively for Media Access Control (MAC) and Physical (PHY) layers using various access technologies according to the BSK, and provides the EKs for respective MAC and PHY layer function modules. With the disclosure, the legality of the equipment is verified by performing an authentication process on the heterogeneous network equipments in one pass, and keys in various MAC layer technologies are managed in a unified way.