5G Multicast-Broadcast Key Management for QoS Flow Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G NR technology lacks effective security measures for multicast and broadcast communications, particularly in ensuring the integrity and encryption of Quality of Service (QoS) flows, which are critical for secure data transmission in wireless communication systems.

Innovation Solution

The implementation of a method and apparatus that manage and distribute multicast-broadcast keys for securing QoS flows in 5G NR networks, involving key generation, distribution, and decoding processes through Service Management Function (SMF) and Radio Access Network (RAN) nodes, ensuring encryption and integrity protection of packets across multiple cells without changing the multicast-broadcast key.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multicast-broadcast keys are updated during cell changes, then security is maintained, but key management complexity and signaling overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network pre-configures multiple multicast-broadcast keys (K1, K2, K3) in the UE before cell changes occur. When a cell change is detected, the UE switches to a pre-configured key without requiring real-time key updates, thereby maintaining security while avoiding the complexity of dynamic key management during mobility events.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If cell-specific keys are derived and distributed for each cell, then security is enhanced, but signaling overhead and network complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidsignaling overhead
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

A single set of multicast-broadcast keys is configured in the UE that can be universally applied across multiple cells. The network does not need to distribute separate cell-specific keys through signaling; instead, the pre-configured keys work across cell boundaries, reducing signaling overhead while maintaining security through key diversity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If multiple multicast-broadcast keys are configured in UE, then security during cell changes is improved, but memory requirements and processing overhead increase

Engineering Contradiction:
Improvesecurity during cell changesVSAvoidmemory requirements
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

Instead of uniformly distributing memory burden across all UEs, the system configures multiple keys only in UEs that are likely to experience cell changes (e.g., UEs in mobility-prone areas or with specific service requirements). This localized approach enhances security where needed while minimizing memory requirements for UEs that do not require such capabilities.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11601805B25G broadcast/multicast security
Publication Date: 2023.03.07 QUALCOMM INC
  • US11601805B2 patent drawing
  • US11601805B2 patent drawing
  • US11601805B2 patent drawing

AI summary

A user equipment (UE) may receive a quality of service (QoS) flow for a multicast or broadcast service that is secured with a multicast-broadcast key. The UE may transmit a data session establishment request to a service management function (SMF) for the multicast or broadcast service. The UE may receive at least one multicast-broadcast key for the PDU session. The UE may determine a radio bearer (RB) configuration for the multicast or broadcast service. The UE may receive one or more QoS flow packets for the multicast or broadcast service over the RB. The UE may decode the one or more QoS flow packets using the at least one multicast-broadcast key, or a key derived from the at least one multicast-broadcast key. Decoding may include decrypting, verifying the integrity, or a combination thereof.