Securing Idle Mode D2D Communication via Network Element ID Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures for device-to-device (D2D) communications in wireless networks are inadequate, especially when one of the peer UEs is in an idle mode, as they lack specified security procedures to prevent eavesdropping and increase power consumption by requiring both UEs to stay in a connected mode for key derivations.

Innovation Solution

A method where the network element encrypts the ID of a connected UE using a key known to both the network and the idle UE, allowing the idle UE to verify the connected UE's ID without transitioning to a connected mode, thereby maintaining security and reducing power consumption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If both UEs stay in connected mode for key derivations, then security verification can be performed, but power consumption increases

Engineering Contradiction:
Improvesecurity verificationVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The network element acts as an intermediary that holds the encryption key and performs the encryption of the second UE's ID. This allows the first UE in idle mode to verify the second UE's ID without needing to establish a direct key derivation connection, thus maintaining security while reducing power consumption.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network element pre-encrypts the second UE's ID using the first key before the first UE needs to verify it. This preliminary encryption action allows the idle mode first UE to perform verification without transitioning to connected mode, resolving the contradiction between security verification and power consumption.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If security procedures are not specified for idle mode UEs, then implementation flexibility is maintained, but security protection is weakened

Engineering Contradiction:
Improveimplementation flexibilityVSAvoidsecurity protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The network element serves as a mediator that provides the encryption service for idle mode UEs. By using the network element as an intermediary, the patent specifies a clear security procedure for idle mode D2D communication while maintaining the flexibility of not requiring both UEs to be in connected mode.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the first UE transitions to connected mode for ID verification, then security can be ensured, but network load increases

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork load
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The network element acts as an intermediary that performs the encryption of the second UE's ID using the first key. This allows the first UE to verify the second UE's ID while remaining in idle mode, thus ensuring security without increasing network load from mode transitions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network element performs the encryption of the second UE's ID in advance, storing it for later verification by the first UE. This preliminary action eliminates the need for the first UE to transition to connected mode for verification, thereby reducing network load while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10462660B2Method, network element, user equipment and system for securing device-to-device communication in a wireless network
Publication Date: 2019.10.29 NOKIA TECHNOLOGIES OY
  • US10462660B2 patent drawing
  • US10462660B2 patent drawing
  • US10462660B2 patent drawing

AI summary

Method, network element, user equipment (UE) and system are disclosed for securing device-to-device (D2D) communication in a wireless network. The wireless network has a first UE in an idle mode, a second UE in a connected mode, and a network element. The method comprises: encrypting the second UE's identification (ID) by using a first key which is known to the network element and the first UE and which is unknown to the second UE; sending the encrypted second UE's ID from the network element to the first UE via the second UE; and verifying the second UE's ID by using the encrypted second UE's ID. According to some embodiments, the method further comprises: deriving a D2D key for D2D communication between the first and second UEs, based on a random number and a second key which is known to the network element and the first UE; encrypting the D2D key based at least in part on a third key which is shared between the network element and the second UE and which is unknown to any other UE in the wireless network; and sending the encrypted D2D key from the network element to the second UE.