D2D Key Exchange for Secure UE Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Device-to-device (D2D) communication in 3GPP networks lacks a security mechanism to protect service data and signaling messages transmitted over the Ud interface, making them vulnerable to tampering.

Innovation Solution

A key exchange method and apparatus that enables user equipment to establish a D2D link by acquiring and sharing keys, using a network device to send keys to user equipment, and employing cryptographic algorithms for encryption and integrity protection, ensuring secure data transmission over the Ud interface.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If D2D communication is enabled for direct UE-to-UE data transmission, then communication efficiency and speed are improved, but security protection capability deteriorates due to lack of security mechanism

Engineering Contradiction:
Improvecommunication speedVSAvoidsecurity protection capability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent applies preliminary action by establishing security context and deriving encryption keys before actual D2D data transmission occurs. The network device derives a D2D communication key from the existing security context between the UE and network, and configures this key to the UE in advance through dedicated signaling, ensuring security protection is ready before direct communication begins.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses the network device as an intermediary to establish security for D2D communication. Although data transmits directly between UEs, the network device mediates the security setup by deriving the encryption key from the existing network-UE security context and distributing it to the UE, thereby providing security protection without interfering with the direct communication path.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security protection mechanism is added to D2D communication, then information security is improved, but system complexity increases

Engineering Contradiction:
Improveinformation securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by reusing the existing security context between the UE and network device for D2D communication security. The same security mechanisms and key derivation functions already used for uplink/downlink protection are leveraged to generate D2D encryption keys, avoiding the need for separate security infrastructure and reducing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses parameter changes by transforming the existing security context parameters (such as uplink integrity protection keys and sequence numbers) into D2D-specific encryption keys through key derivation functions. This allows the system to adapt existing security parameters for a new communication mode without introducing entirely new security mechanisms.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11777716B2Key exchange method and apparatus
Publication Date: 2023.10.03 HUAWEI TECH CO LTD
  • US11777716B2 patent drawing
  • US11777716B2 patent drawing
  • US11777716B2 patent drawing

AI summary

Embodiments of the present invention disclose a key exchange method and apparatus. A network device acquires a first key, and sends a message including the first key to a second user equipment, so that the second user equipment uses, when communicating with a first user equipment by using a D2D link, the first key to protect transmitted information.