Direct-Communication Key Generation for Sidelink Positioning Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security mechanisms for direct communication in sidelink positioning services are inadequate as UEs involved in these services are not bound to specific application services, making it impractical to provide long-term credentials, thus compromising security.
Innovation Solution
A method for generating a direct communication intermediate key shared by UEs, utilizing first and second key-related information to establish integrity and encryption protection for sidelink positioning services, involving a first UE, a second UE, and positioning key management functions (PKMFs) to generate session keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If long-term valid credentials are provided to all UEs for SL positioning service, then security protection is established, but it becomes impractical and unsafe since any UE may be involved in the service
Solution Approach 1:
The patent applies preliminary action by pre-configuring root keys in UEs before they participate in SL positioning services. These root keys serve as foundational credentials that enable dynamic key generation when needed, rather than requiring pre-established long-term credentials for all possible UE combinations. This allows UEs to be flexibly assigned roles (positioning UE or target UE) while maintaining security through on-demand key derivation.
Solution Approach 2:
The patent introduces an intermediary mechanism through the use of root keys and positioning service codes that mediate between the need for security and UE flexibility. The root key acts as a trusted intermediary that enables the generation of session-specific keys (K_SL positioning 1st, K_SL positioning 2nd) without requiring direct long-term credential sharing between UEs. This intermediary approach allows dynamic security establishment for any UE pair involved in positioning services.
2Reliability
If dynamic session keys are generated for each UE pair, then security is improved for flexible UE involvement, but key management complexity increases
Solution Approach 1:
The patent applies segmentation by dividing the key management structure into hierarchical levels: root keys (pre-configured in UEs), positioning service codes (identifying specific services), and derived session keys (K_SL positioning 1st, K_SL positioning 2nd). This segmentation allows complex security requirements to be met through structured, modular key derivation rather than monolithic key management, reducing overall system complexity while maintaining strong security for dynamic UE pairs.
Data Source
Figure 1~2
Figure 3~4
Figure 5~6
AI summary
The present disclosure relates to the field of communications. Provided are a direct-communication key generation method and apparatus, which can be applied to communication systems such as a long term evolution (LTE) system, a fifth generation mobile communication system, a 5G new radio (NR) system, or other new mobile communication systems in the future. The method comprises: sending a direct communication request to a second UE, wherein the direct communication request comprises first key-related information; receiving second key-related information from the second UE; and generating a direct-communication intermediate key according to the first key-related information and the second key-related information. By means of the technique in the present disclosure, a direct-communication intermediate key which can be shared by a first UE and a second UE can be generated, such that integrity protection and/or encryption protection for direct communication of a ranging link positioning service between the first UE and the second UE can be realized according to the direct-communication intermediate key, thereby improving the security of data transmission in the direct communication of the ranging link positioning service.