Direct Communication Key Establishment via GBA Push
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Pre-configuring shared keys for ProSe Direct Communication between User Equipment devices and UE-to-Network Relays is complex due to the need to cover various devices and network scenarios, including different Home PLMNs and roaming situations, making it challenging to establish secure communication without network coverage.
Innovation Solution
The method involves using the Generic Bootstrapping Architecture (GBA) Push procedure to derive a direct communication key by exchanging identifiers and key generation information between User Equipment devices and UE-to-Network Relays, utilizing a Key Derivation Function (KDF) and Message Authentication Codes, enabling secure communication even when devices are out of network coverage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If pre-configured shared keys are used for ProSe Direct Communication, then secure communication can be established, but the complexity of key management increases significantly to cover all devices and network scenarios
Solution Approach 1:
The patent introduces a key management server as an intermediary that centralizes the key management functionality. Instead of each device needing to pre-configure keys with every other device, the key management server dynamically generates and distributes session keys based on device identifiers and communication context, significantly reducing the complexity of key management while maintaining security.
Solution Approach 2:
The patent changes the approach from static pre-configured keys to dynamic session keys that are generated based on varying parameters such as device identifiers, communication partners, and network context. This allows the same system to handle multiple communication scenarios without requiring separate pre-configured keys for each case.
2Adaptability or versatility
If pre-configured shared keys are used for all possible communication paths, then all devices can communicate securely, but the process of pre-configuring keys becomes extremely complex
Solution Approach 1:
The system enables self-service key establishment where devices automatically obtain the necessary cryptographic material through interaction with the key management server. Devices use their identifiers and communication context to request session keys, eliminating the need for manual or complex pre-configuration processes while maintaining comprehensive communication coverage.
Solution Approach 2:
The key management server performs preliminary key generation and distribution actions before actual communication occurs. By pre-generating session keys based on device identifiers and communication scenarios, the system prepares the cryptographic material in advance without requiring complex configuration processes, enabling devices to communicate securely upon first contact.
3Device complexity
If devices derive session shared keys dynamically, then key management complexity is reduced, but additional key derivation steps are required
Solution Approach 1:
The key management server performs preliminary key generation and distribution before actual communication begins. By pre-computing session keys based on device identifiers and communication context, the system reduces the time required during actual communication establishment, as devices receive ready-to-use cryptographic material rather than needing to perform complex derivations in real-time.
Data Source
AI summary
Methods And Apparatus For Direct Communication Key Establishment Methods (100, 200, 300) and apparatus (400, 500, 600, 700, 800, 900) are disclosed for establishing a key for direct communication between a User Equipment device, UE, and a device. The methods and apparatus cooperate to form a system for securing direct communication between a UE and a device over an interface. The system comprises a UE (20), a device (30) and a Direct Communication Element (40). The Direct Communication Element (40) is configured to obtain a shared session key and Generic Bootstrapping Architecture Push Information, GPI, to derive a direct communication key from at least the shared session key, and to send the direct communication key and the GPI to the device (30). The device (30) is configured to send the GPI to the UE (20). The UE (20) is configured to derive the shared session key from at least the GPI and to derive the direct communication key from the shared session key. Also disclosed are a computer product operable to carry out methods according to the present invention and a computer program product comprising a computer readable medium having such a computer product stored thereon.


