5G UE Relay Security via Credential Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G mobile communication, the relay terminal in UE-to-UE relay communication lacks security measures, making it vulnerable to eavesdropping or alteration of signals transmitted between end terminals.

Innovation Solution

A method is introduced where the first UE performs relay communication by transmitting a request message including UE ID, Relay information, UE type information, and UE public key information to an application server through a 5G core network, receiving a security-related message, establishing a secure link with the relay UE, and setting up a secure channel in the IP layer with the second UE.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If UE-to-UE relay communication is implemented to extend coverage and enable communication between distant terminals, then communication availability and coverage are improved, but security vulnerability increases due to the relay terminal's ability to eavesdrop or alter signals

Engineering Contradiction:
Improvecommunication availabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the communication system into distinct roles: relay terminals that provide coverage extension and end terminals that maintain security. By separating these functions, the system allows relay terminals to extend coverage without compromising the security of end-to-end communication between authorized users.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an application server as an intermediary that manages security credentials and authentication. This mediator distributes credential information to relay terminals and end terminals, enabling secure communication while maintaining the relay functionality for coverage extension.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If relay terminals receive and forward both uplink and downlink signals between end terminals, then communication functionality is improved, but security risk increases due to potential signal interception or modification

Engineering Contradiction:
Improvecommunication functionalityVSAvoidsignal interception risk
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The patent implements preliminary security measures by distributing credential information to relay terminals and end terminals before communication begins. This advance preparation includes establishing authentication mechanisms and security contexts, ensuring that when relay terminals forward signals, the communication is already protected against interception or modification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies different security qualities to different parts of the communication system. Relay terminals receive and process credential information locally to establish secure contexts, while end terminals use these credentials to protect their communication. This localized security approach allows functional relay operation while maintaining security integrity.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12317073B2Relay communication
Publication Date: 2025.05.27 LG ELECTRONICS INC
  • US12317073B2 patent drawing
  • US12317073B2 patent drawing
  • US12317073B2 patent drawing

AI summary

A disclosure of the present specification provides a method for performing relay communication by a first UE. The method may comprise the steps of: transmitting a request message including UE ID, relay information, UE type information, and UE public key information to an application server through a 5G core network; receiving, from the application server, a security-related message in response to the request message; establishing a security link with the relay UE on the basis of first credential information; and receiving an IP message for configuring a security channel in an IP layer from a second UE.