D2D Group Communication Security Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current D2D group communication systems face limitations in supporting multiple PDCP/RLC entities per destination, leading to issues with counter and security key management, and are vulnerable to replay attacks due to the lack of signaling between UEs, particularly in ProSe-based public safety communications.
Innovation Solution
A method and system for managing packet counters and security keys across multiple PDCP entities within a service group, where a new ProSe traffic key and encryption key are generated for each new PDCP entity, and counters are updated for each data packet, ensuring secure encryption and preventing key reuse, while also mitigating replay attacks through proper key management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a single PTK and counter are used for one destination as per current key hierarchy, then the scheme works for single PDCP entity, but it cannot support multiple PDCP entities per destination leading to key reuse and security vulnerabilities
Solution Approach 1:
The patent segments the security key management by creating separate PTK instances for each PDCP entity while maintaining a shared counter mechanism. This allows multiple PDCP entities to operate independently with unique key-counter pairs, preventing key reuse across different entities while maintaining coordination through the shared counter space.
Solution Approach 2:
The patent introduces a new dimension to key management by incorporating the PDCP entity identifier into the key derivation process. Instead of a flat key structure, it creates a hierarchical dimension where keys are derived based on both the destination and the specific PDCP entity, enabling differentiation and security for multiple entities sharing the same destination.
2Reliability
If multiple PTKs are generated for multiple PDCP entities, then security is improved, but device complexity increases due to enhanced key management requirements
Solution Approach 1:
The patent implements a universal counter mechanism that serves multiple PDCP entities simultaneously. The shared counter provides sequence numbering for all entities while the key derivation function universally handles the creation of entity-specific PTKs, reducing the need for separate complex management systems for each entity.
Solution Approach 2:
The patent changes the parameters used in key derivation to include both destination identifier and PDCP entity identifier. This parameter expansion allows the system to generate unique keys for each entity without requiring fundamentally different key management approaches, simply by modifying the input parameters to the derivation function.
3Reliability
If counters are updated for every packet transmitted, then encryption uniqueness is ensured, but overhead increases due to counter management and transmission
Solution Approach 1:
The patent merges the counter management function across multiple PDCP entities by implementing a shared counter mechanism. Instead of maintaining separate counters for each entity, the system combines them into a single counter space that serves all entities, reducing the overall counter management overhead while maintaining encryption uniqueness through the combination of counter values with entity-specific keys.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method of a user equipment, UE, in a communication system, the method comprising: acquiring a first key for a group to which the UE belongs and an algorithm identifier, ID, indicating an algorithm used for protecting data; acquiring an ID associated with a first entity; generating a second key based on the first key; generating a third key based on the second key; and protecting the data based on the algorithm, and at least one of the third key and the ID associated with the first entity, wherein at least one other entity generated for the group uses the second key.