Direct Communication Key Derivation Using GBA Transaction Identifiers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Establishing a shared key for direct communication between User Equipment (UE) and devices in ProSe (Proximity Services) is challenging due to the complexity of pre-configuring keys for various devices and network scenarios, especially when UE is out of network coverage or GBA procedures are not available.
Innovation Solution
The method involves using a transaction identifier from a previous Generic Bootstrapping Architecture (GBA) procedure as a temporary ID to initiate a GBA Push procedure, where a Direct Communication Element derives a direct communication key using a Key Derivation Function (KDF) with session shared key and device identifier, enabling secure communication over ProSe interfaces.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If pre-configured shared keys are used for ProSe Direct Communication, then security is established, but key management complexity increases significantly
Solution Approach 1:
The patent introduces a key derivation mechanism using transaction identifiers from GBA procedures as an intermediary. Instead of directly managing complex shared keys between all device pairs, the system uses transaction identifiers as mediators that can be easily exchanged and derived into session keys, significantly simplifying key management while maintaining security
Solution Approach 2:
The patent performs preliminary key material establishment through GBA bootstrapping procedures before direct communication begins. Transaction identifiers are obtained in advance during network attachment, and these pre-obtained identifiers are then used to derive communication keys, eliminating the need for real-time complex key negotiation
2Ease of operation
If transaction identifier is used to identify UE, then key establishment is simplified, but reliability decreases when transaction identifier is invalid
Solution Approach 1:
The patent prepares alternative identification mechanisms in advance. When the transaction identifier becomes invalid (e.g., after GBA procedure completion), the system has pre-configured fallback methods including using device identifiers combined with key derivation functions, ensuring continuous operational reliability without interrupting key establishment
Solution Approach 2:
The patent dynamically changes identification parameters based on validity status. When transaction identifier is valid, it is used for key derivation; when invalid, the system transitions to using device identifiers or other alternative parameters, maintaining flexibility and reliability across different operational states
Data Source
AI summary
A method, performed by a User Equipment device, UE, for obtaining a key for direct communication with a device over an air interface, wherein the UE has previously acquired a transaction identifier received from a Bootstrapping Server Function, BSF, in a Generic Bootstrapping Architecture, GBA, procedure, is provided. The method comprises storing the transaction identifier, sending the transaction identifier to the device and requesting key generation for direct communication with the device. If the transaction identifier is invalid, the method further comprises receiving from the device a device identifier and key generation information, deriving a session shared key from at least the key generation information, and deriving a direct communication key from at least the session shared key and the device identifier.


