5G Multicast-Broadcast Key Refresh Mechanism
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 5G NR technology lacks effective mechanisms for securely managing and refreshing multicast-broadcast security keys, particularly in scenarios involving changes in user equipment (UE) mobility and group membership, which can compromise the security and integrity of broadcast services.
Innovation Solution
The implementation of a method and apparatus for managing and refreshing multicast-broadcast security keys, where a Session Management Function (SMF) generates and distributes new keys based on service policies, using non-access stratum (NAS) and radio resource control (RRC) signaling, ensuring secure decoding of packets across cell changes without altering the key, and deriving cell-specific keys from root keys for enhanced security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Duration of action of stationary object
If multicast-broadcast security keys are maintained static for cell mobility, then decoding continuity is improved, but security integrity deteriorates due to group membership changes
Solution Approach 1:
The patent implements periodic key refresh mechanisms where multicast-broadcast keys are updated at predetermined intervals or upon specific triggering events (cell change, group membership change). This periodic action maintains security integrity while ensuring decoding continuity through proper key distribution to UEs.
Solution Approach 2:
The patent introduces dynamic key management where the multicast-broadcast key can change based on UE mobility events and group membership changes. The system adapts key validity duration and refresh timing dynamically, transitioning from static to dynamic key management to balance security and continuity requirements.
2Reliability
If multicast-broadcast keys are refreshed frequently, then security integrity is improved, but decoding continuity worsens due to key synchronization issues during cell changes
Solution Approach 1:
The patent implements preliminary key distribution mechanisms where updated multicast-broadcast keys are provided to UEs in advance or simultaneously with cell change events. This preliminary action ensures UEs have the correct key before decoding operations begin, preventing synchronization issues while maintaining frequent key refresh rates.
Solution Approach 2:
The patent establishes feedback mechanisms where the network monitors UE key reception and decoding status, then adjusts key refresh timing and distribution methods accordingly. This feedback loop ensures security integrity is maintained while preventing decoding continuity disruptions during cell changes.
3Reliability
If cell-specific keys are derived for each cell, then security integrity is improved, but device complexity increases due to multiple key management operations
Solution Approach 1:
The patent segments the overall security key into multiple components: a group-specific master key and cell-specific derived keys. This segmentation allows the system to maintain high security integrity through cell-specific keys while reducing management complexity by separating the key hierarchy into manageable segments that can be distributed and updated independently.
Data Source
AI summary
A user equipment (UE) may update multicast-broadcast key for securing a data session for a multicast or broadcast service. The UE may receive a multicast-broadcast key for the for a multicast or broadcast service carried by a radio bearer (RB) associated with the data session. The UE may receive packets for the multicast or broadcast service. The UE may decode the packets using the multicast-broadcast key, or a key derived from the multicast-broadcast key. The UE may receive an updated multicast-broadcast key for the multicast or broadcast service. The UE may decode the packets for the multicast or broadcast service received on the RB using the updated multicast-broadcast key, or a key derived from the updated multicast-broadcast key.


