D2D Group Communication Security Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current D2D group communication systems face limitations in supporting multiple PDCP/RLC entities per destination, leading to issues with counter and security key management, and are vulnerable to replay attacks due to the lack of signaling between UEs, particularly in ProSe-based public safety communications.

Innovation Solution

A method and system for managing packet counters and security keys across multiple PDCP entities within a service group, where a new ProSe traffic key and encryption key are generated for each new PDCP entity, and counters are updated for each data packet, ensuring secure encryption and preventing key reuse, while also mitigating replay attacks through proper key management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single PTK and counter are used for one destination as per current key hierarchy, then the scheme works for single PDCP entity, but it cannot support multiple PDCP entities per destination leading to key reuse and security vulnerabilities

Engineering Contradiction:
Improvesupport for multiple PDCP entities per destinationVSAvoidsecurity against replay attacks and key reuse
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the security key management by creating separate PTK instances for each PDCP entity while maintaining a shared counter mechanism. This allows multiple PDCP entities to operate independently with unique key-counter pairs, preventing key reuse across different entities while maintaining coordination through the shared counter space.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension to key management by incorporating the PDCP entity identifier into the key derivation process. Instead of a flat key structure, it creates a hierarchical dimension where keys are derived based on both the destination and the specific PDCP entity, enabling differentiation and security for multiple entities sharing the same destination.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If multiple PTKs are generated for multiple PDCP entities, then security is improved, but device complexity increases due to enhanced key management requirements

Engineering Contradiction:
Improvesecurity against replay attacksVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal counter mechanism that serves multiple PDCP entities simultaneously. The shared counter provides sequence numbering for all entities while the key derivation function universally handles the creation of entity-specific PTKs, reducing the need for separate complex management systems for each entity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the parameters used in key derivation to include both destination identifier and PDCP entity identifier. This parameter expansion allows the system to generate unique keys for each entity without requiring fundamentally different key management approaches, simply by modifying the input parameters to the derivation function.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If counters are updated for every packet transmitted, then encryption uniqueness is ensured, but overhead increases due to counter management and transmission

Engineering Contradiction:
Improveencryption uniquenessVSAvoidcounter management overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the counter management function across multiple PDCP entities by implementing a shared counter mechanism. Instead of maintaining separate counters for each entity, the system combines them into a single counter space that serves all entities, reducing the overall counter management overhead while maintaining encryption uniqueness through the combination of counter values with entity-specific keys.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3754897B1System and method of counter management and security key update for device-to-device group communication
Publication Date: 2021.09.29 SAMSUNG ELECTRONICS CO LTD
  • EP3754897B1 patent drawingFigure 1
  • EP3754897B1 patent drawingFigure 2
  • EP3754897B1 patent drawingFigure 3

AI summary

A method of a user equipment, UE, in a communication system, the method comprising: acquiring a first key for a group to which the UE belongs and an algorithm identifier, ID, indicating an algorithm used for protecting data; acquiring an ID associated with a first entity; generating a second key based on the first key; generating a third key based on the second key; and protecting the data based on the algorithm, and at least one of the third key and the ID associated with the first entity, wherein at least one other entity generated for the group uses the second key.