Device-to-Device Discovery Using Identity-Based Cryptography

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication systems lack secure device-to-device discovery and communication mechanisms, particularly in scenarios where devices are out of network coverage and there is no common root of trust, posing security risks for ProSe direct discovery and communication.

Innovation Solution

The implementation of identity-based cryptography mechanisms, such as Elliptic Curve-based Certificateless Signatures for Identity-based Encryption (ECCSI) and Sakai-Kasahara Key Encryption (SAKKE) algorithms, for mutual authentication and key agreement over the PC5 interface, ensuring secure device-to-device communication even without a common root of trust.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional wireless communication systems are used for device-to-device discovery and communication, then devices can communicate over the air interface, but security is compromised when devices are out of network coverage and lack a common root of trust

Engineering Contradiction:
ImprovesecurityVSAvoidout-of-coverage operation
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a mediator mechanism where devices exchange and verify public keys through discovery messages. This intermediary key exchange process enables secure communication without requiring continuous network coverage or a common root of trust, as each device independently verifies the other's identity through cryptographic signatures embedded in discovery messages.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authentication by establishing security associations and exchanging cryptographic credentials during the discovery phase before actual communication begins. Devices perform mutual authentication and key agreement in advance, ensuring that when out-of-coverage scenarios occur, the security framework is already in place without requiring real-time network verification.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If identity-based cryptography mechanisms are implemented for secure device-to-device communication, then security and integrity are enhanced in out-of-coverage scenarios, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidcryptography implementation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent employs universal cryptographic algorithms (ECCSI and SAKKE) that can be implemented across diverse device types and scenarios. These multi-functional algorithms provide both authentication and key agreement capabilities in a unified framework, reducing the need for multiple separate cryptographic implementations and thereby limiting the increase in device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent replaces complex mechanical or procedural security verification mechanisms with mathematical cryptography-based authentication. By substituting physical security infrastructure (like trusted network anchors) with cryptographic proof mechanisms, the system achieves enhanced security without requiring proportional increases in physical device complexity or infrastructure.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS9893894B2Systems, methods, and devices for secure device-to-device discovery and communication
Publication Date: 2018.02.13 APPLE INC
  • US9893894B2 patent drawing
  • US9893894B2 patent drawing
  • US9893894B2 patent drawing

AI summary

A user equipment (UE) is configured to send a direct communication request to a peer UE, wherein the direct communication request comprises a signature authenticating an identity of the UE. The UE is configured to process a direct communication response from the peer UE to authenticate an identity of the peer UE, wherein the direct communication response comprises a signature authenticating the identity of the peer UE. In response to processing the direct communication response from the peer UE to authenticate the identity of the peer UE, the UE is configured to engage in direct communication with the peer UE.