D2D Key Management Entity for Signaling Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network-controlled device-to-device (D2D) communication systems face high signaling burdens on the core network due to the need for core network involvement in key generation and management for D2D connections, especially when a large number of devices are engaged in D2D communications.
Innovation Solution
A method where a first user equipment derives a first key based on security parameters shared with the core network and sends a notification to a second user equipment, allowing the access network to generate a second key for D2D communication, thereby reducing the core network's signaling burden by enabling key generation and distribution within the access network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the core network manages and controls key generation for every D2D connection, then security protection is ensured, but the signaling burden of the core network increases significantly
Solution Approach 1:
The patent segments the key management functionality by introducing a D2D key management entity that operates independently from the core network's mobility management entity. This segmentation allows security key generation to be handled locally by the D2D key management entity rather than requiring core network involvement for every D2D connection, thus reducing signaling burden while maintaining security protection through dedicated key management infrastructure.
Solution Approach 2:
The patent introduces a D2D key management entity as an intermediary between the core network and D2D communicating devices. This intermediary handles key generation and distribution locally, reducing the need for direct core network involvement in each D2D connection establishment while ensuring security through controlled key management. The intermediary resolves the contradiction by providing security services without imposing core network signaling burden.
2Reliability
If the core network is involved in every key negotiation of D2D connections, then security is maintained, but key generation delays increase
Solution Approach 1:
The patent implements preliminary action by having the D2D key management entity pre-generate and store security keys before D2D connections are established. When devices need to communicate, they can retrieve pre-generated keys from the local D2D key management entity rather than waiting for core network key generation and distribution. This preliminary key preparation significantly reduces key generation delays while maintaining security through controlled key management.
Solution Approach 2:
The D2D key management entity acts as an intermediary that provides rapid local key generation and distribution, eliminating the need for time-consuming core network involvement in each key negotiation. The intermediary maintains security while reducing delays by handling key management operations locally with pre-prepared security contexts and keys.
3Reliability
If core network apparatus generates keys for all D2D communications, then centralized security control is achieved, but the system scalability is limited when huge number of UEs conduct D2D communications
Solution Approach 1:
The patent segments the centralized key management function by introducing distributed D2D key management entities at the network edge, closer to D2D communicating devices. Each D2D key management entity handles key generation and distribution for its local area, providing decentralized operation that scales with the number of D2D connections. This segmentation maintains security control while enabling the system to handle huge numbers of simultaneous D2D communications without overwhelming the core network.
Solution Approach 2:
The patent transitions from a single-dimensional core network-centric key management model to a multi-dimensional architecture with D2D key management entities distributed across the network. This dimensional change allows the system to scale horizontally by adding more local key management entities rather than increasing core network capacity, thereby improving productivity and scalability while maintaining security through distributed control.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Methods and apparatus are provided for securing device-to-device communications. A method can comprise: at an access network apparatus, obtaining from a core network apparatus and storing a first key shared between a first user equipment and the core network apparatus for device-to-device communications of the first user equipment; receiving from a second user equipment, a request for generating a second key for a device-to-device communication between the first user equipment and the second user equipment; in response to the request, generating the second key based on the first key and security parameters; and sending the second key to the second user equipment.