D2D Security Key Management via MME Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In Device-to-Device (D2D) communication systems, there is a need for secure key management to protect against passive and active attackers intercepting or modifying data packets, as existing systems lack effective ciphering, replay protection, and integrity protection mechanisms.

Innovation Solution

A method and apparatus for managing and establishing security keys in D2D communication systems, where User Equipments (UEs) transmit key request messages to a server through a Mobility Management Entity (MME), derive security keys using secret keys and security parameters, and maintain these keys for secure communication during connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If D2D communication is implemented to enable direct one-to-one communication between UEs, then communication efficiency and user experience are improved, but security vulnerability increases due to lack of ciphering and integrity protection mechanisms

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidsecurity reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by establishing security keys and authentication mechanisms before D2D communication begins. The network controller pre-generates security parameters and distributes them to UEs, ensuring that ciphering and integrity protection are already in place before data transmission starts, thus preventing security vulnerabilities from arising during communication

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a network controller as an intermediary that manages security key distribution and authentication between UEs. This mediator ensures that even though UEs communicate directly, security functions are performed by a trusted network entity that generates and manages security parameters, thereby maintaining security reliability while enabling direct communication

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security keys are established through network controller to protect D2D communication, then security reliability is improved, but system complexity increases due to additional key management protocols

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges security key management functions with existing network control structures. The network controller, which already manages UE connections and mobility, is extended to also handle security parameter generation and distribution. This consolidation avoids creating a separate complex security infrastructure while maintaining security reliability

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The network controller is designed to perform multiple functions including connection management, mobility management, and security key management. By making the network controller universal, the patent avoids adding separate dedicated security entities, thereby improving security reliability without proportionally increasing system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10257698B2Method and apparatus for managing security key in a near field D2D communication system
Publication Date: 2019.04.09 SAMSUNG ELECTRONICS CO LTD
  • US10257698B2 patent drawing
  • US10257698B2 patent drawing
  • US10257698B2 patent drawing

AI summary

The present disclosure relates to a pre-5th-Generation (5G) or 5G communication system to be provided for supporting higher data rates Beyond 4th-Generation (4G) communication system such as Long Term Evolution (LTE). The present disclosure further relates to a method and apparatus for managing a security key in a communication system are provided. The method includes transmitting a first key request message including an identifier (ID) of an originating user equipment (UE) to a server through a mobility management entity (MME), receiving a key response message including security parameters and a secret key of the originating UE from the server, determining a security key based on the security parameters and the secret key of the originating UE by the originating UE, and communicating with a terminating UE based on the security key by the originating UE, while a connection between the originating UE and the terminating UE is maintained.