End-to-End Security Establishment in 5G Relay Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless communication systems, particularly in 5G networks, establishing end-to-end security between user equipment (UEs) that communicate via a relay is challenging, as existing methods lack efficient mechanisms for ensuring integrity and confidentiality of messages across multiple terminals.

Innovation Solution

A method and apparatus are introduced to establish end-to-end security by transmitting request messages for security information between terminals, generating session keys, and configuring controllers to manage security protocols, enabling secure communication through a relay terminal.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing security methods are used for relay communication, then device complexity is reduced, but reliability of end-to-end security is insufficient

Engineering Contradiction:
Improveend-to-end securityVSAvoidsecurity protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security establishment process into distinct phases: first establishing security between the first terminal and relay terminal using first security information, then establishing security between the relay terminal and second terminal using second security information. This segmentation allows complex end-to-end security to be broken down into manageable parts while maintaining overall reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary security establishment actions by first configuring security between the first terminal and relay terminal before the relay terminal communicates with the second terminal. This preliminary action ensures that security foundations are laid in advance, improving overall end-to-end security reliability without requiring complex simultaneous security protocols.

Inventive Principle:
Principle #10Preliminary action

2Loss of information

If simple security protocols are used, then ease of operation is improved, but loss of information increases due to insufficient integrity and confidentiality protection

Engineering Contradiction:
Improvemessage integrity and confidentialityVSAvoidsecurity configuration
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The relay terminal acts as an intermediary that independently manages second security information for communication with the second terminal, while the first terminal manages first security information. This intermediary structure protects message integrity and confidentiality by ensuring that each terminal has dedicated security credentials, preventing information loss without requiring complex end-to-end security configuration at each terminal.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Each terminal (first terminal and second terminal) independently manages its own security information without requiring complex end-to-end security configuration. The first terminal manages first security information and the second terminal manages second security information, allowing simple operation while maintaining strong integrity and confidentiality protection through distributed security management.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20230188360A1Method and apparatus for establishing end-to-end security in wireless communication system
Publication Date: 2023.06.15 SAMSUNG ELECTRONICS CO LTD
  • US20230188360A1 patent drawing
  • US20230188360A1 patent drawing
  • US20230188360A1 patent drawing

AI summary

The disclosure relates to a 5G or 6G communication system for supporting a higher data transmission rate. Disclosed is a method of a first terminal in a wireless communication system including transmitting a first request message for information required for establishing security between terminals to a first entity, receiving a first response message including the information required for establishing security between terminals from the first entity in response to the first request message, generating security information for the first terminal, based on the response message, transmitting a second request message including the security information for the first terminal to a relay terminal, establishing security with the relay terminal, receiving a second response message including security information for a second terminal from the relay terminal in response to the second request message, and generating an end-to-end session key between terminals, based on the received security information for the second terminal.