WN-Specific Key System for Wireless Network Access Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional 3G/4G wireless networks face increased latency and overhead during handovers in densely deployed environments due to frequent transfers of UE-specific keys, which do not provide adequate access protection for wireless connections between user equipment (UE) and the Radio Access Network (RAN).

Innovation Solution

Implementing a wireless network-specific key (WN-specific key) system that provides multi-level access protection by assigning WN-specific keys to wireless networks, distributing them to base stations, and using them to encrypt/decrypt data over radio access links, in conjunction with UE-specific keys for bearer channels, reducing the need for frequent key exchanges during handovers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If UE-specific keys are transferred during handovers in conventional 3G/4G wireless networks, then access protection for bearer channels is maintained, but latency and overhead increase significantly in densely deployed environments

Engineering Contradiction:
Improveaccess protectionVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the encryption key hierarchy into two levels: network-specific keys (WN-keys) that are common across multiple UEs and UE-specific keys (UE-keys) that are unique to each user. This segmentation allows the system to maintain security for individual bearers while using shared keys for radio access protection, thereby reducing the frequency of key transfers during handovers and decreasing latency.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The network-specific key serves multiple functions: it provides access protection for the radio access link shared by multiple UEs, and acts as a parent key from which UE-specific keys are derived. This multi-functionality reduces the need for frequent key exchanges during handovers, as the WN-key remains stable across handovers while still enabling secure communication for multiple users.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If UE-specific keys are transferred during handovers, then bearer channel security is maintained, but key exchange frequency increases in densely deployed environments

Engineering Contradiction:
ImprovesecurityVSAvoidmobility management efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

By segmenting keys into network-specific and UE-specific layers, the patent enables the radio access network to use stable network-specific keys for protection during handovers, while only transferring necessary UE-specific keys when needed. This reduces the frequency of key exchanges and improves mobility management efficiency.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary key derivation where UE-specific keys are derived from network-specific keys in advance. This preliminary action allows the system to maintain security without requiring frequent re-keying during handovers, as the derived UE-keys can be reused across handovers if the WN-key remains stable.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If conventional key distribution is used, then bearer channel protection is provided, but separate access protection for radio access links is not achieved

Engineering Contradiction:
Improveaccess protectionVSAvoidencryption architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation to create a hierarchical key architecture with network-specific keys at the top level and UE-specific keys at the bottom level. This segmentation enables separate access protection for radio access links using network-specific keys, while maintaining bearer channel protection through UE-specific keys, achieving the desired security without excessive complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a nested key structure where UE-specific keys are derived from and nested within the network-specific key framework. This nesting allows the system to provide multiple levels of protection (radio access link protection and bearer channel protection) while sharing the burden of key management, thereby achieving comprehensive security without proportional increase in complexity.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS11121862B2System and method for wireless network access protection and security architecture
Publication Date: 2021.09.14 HUAWEI TECH CO LTD
  • US11121862B2 patent drawing
  • US11121862B2 patent drawing
  • US11121862B2 patent drawing

AI summary

Wireless network specific (WN-specific) key can be used to provide access protection over the radio access link. A WN-specific key may be associated with (or assigned to) a wireless network, and distributed to access points of the wireless network, as well as to user equipments (UEs) following UE authentication. The WN-specific key is then used to encrypt/decrypt data transported over the radio access link. The WN-specific key can be used in conjunction with the UE-specific keys to provide multi-level access protection. In some embodiments, WN-specific kays are shared between neighboring wireless networks to reduce the frequency of key exchanges during handovers. Service-specific keys may be used to provide access protection to machine to machine (M2M) services. Group-specific keys may be used to provide access protection to traffic communicated between members of a private social network.