D2D Key Management Entity for Signaling Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network-controlled device-to-device (D2D) communication systems face high signaling burdens on the core network due to the need for core network involvement in key generation and management for D2D connections, especially when a large number of devices are engaged in D2D communications.

Innovation Solution

A method where a first user equipment derives a first key based on security parameters shared with the core network and sends a notification to a second user equipment, allowing the access network to generate a second key for D2D communication, thereby reducing the core network's signaling burden by enabling key generation and distribution within the access network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the core network manages and controls key generation for every D2D connection, then security protection is ensured, but the signaling burden of the core network increases significantly

Engineering Contradiction:
Improvesecurity protectionVSAvoidsignaling burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the key management functionality by introducing a D2D key management entity that operates independently from the core network's mobility management entity. This segmentation allows security key generation to be handled locally by the D2D key management entity rather than requiring core network involvement for every D2D connection, thus reducing signaling burden while maintaining security protection through dedicated key management infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a D2D key management entity as an intermediary between the core network and D2D communicating devices. This intermediary handles key generation and distribution locally, reducing the need for direct core network involvement in each D2D connection establishment while ensuring security through controlled key management. The intermediary resolves the contradiction by providing security services without imposing core network signaling burden.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the core network is involved in every key negotiation of D2D connections, then security is maintained, but key generation delays increase

Engineering Contradiction:
ImprovesecurityVSAvoidkey generation delays
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by having the D2D key management entity pre-generate and store security keys before D2D connections are established. When devices need to communicate, they can retrieve pre-generated keys from the local D2D key management entity rather than waiting for core network key generation and distribution. This preliminary key preparation significantly reduces key generation delays while maintaining security through controlled key management.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The D2D key management entity acts as an intermediary that provides rapid local key generation and distribution, eliminating the need for time-consuming core network involvement in each key negotiation. The intermediary maintains security while reducing delays by handling key management operations locally with pre-prepared security contexts and keys.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If core network apparatus generates keys for all D2D communications, then centralized security control is achieved, but the system scalability is limited when huge number of UEs conduct D2D communications

Engineering Contradiction:
Improvecentralized security controlVSAvoidsystem scalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the centralized key management function by introducing distributed D2D key management entities at the network edge, closer to D2D communicating devices. Each D2D key management entity handles key generation and distribution for its local area, providing decentralized operation that scales with the number of D2D connections. This segmentation maintains security control while enabling the system to handle huge numbers of simultaneous D2D communications without overwhelming the core network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from a single-dimensional core network-centric key management model to a multi-dimensional architecture with D2D key management entities distributed across the network. This dimensional change allows the system to scale horizontally by adding more local key management entities rather than increasing core network capacity, thereby improving productivity and scalability while maintaining security through distributed control.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentEP3014801B1Methods and apparatus for generating keys in device-to-device communications
Publication Date: 2019.10.30 NOKIA TECHNOLOGIES OY
  • EP3014801B1 patent drawingFigure 1
  • EP3014801B1 patent drawingFigure 2
  • EP3014801B1 patent drawingFigure 3

AI summary

Methods and apparatus are provided for securing device-to-device communications. A method can comprise: at an access network apparatus, obtaining from a core network apparatus and storing a first key shared between a first user equipment and the core network apparatus for device-to-device communications of the first user equipment; receiving from a second user equipment, a request for generating a second key for a device-to-device communication between the first user equipment and the second user equipment; in response to the request, generating the second key based on the first key and security parameters; and sending the second key to the second user equipment.