Dynamic Group User Key Identifier for 3GPP MCS Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 3GPP MCS networks, receiving clients can identify and link communications from a transmitting client using its group user key identifier, compromising security when the network spans multiple security domains.

Innovation Solution

A method where the transmitting client dynamically generates a new group user key identifier for each predetermined event, ensuring that encrypted content can be decrypted by receiving clients without linking communications to the same transmitting entity, while maintaining endpoint diversity encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the transmitting client uses a fixed group user key identifier for encryption, then the receiving client can reliably decrypt the content, but the receiving client can identify and track the transmitting client across multiple communications

Engineering Contradiction:
Improvecontent decryption reliabilityVSAvoidclient tracking and identification
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies dynamics by making the group user key identifier variable rather than fixed. The transmitting client dynamically generates a new group user key identifier for each communication session, allowing the system to adapt between reliability (through consistent encryption mechanism) and anonymity (through changing identifiers). This resolves the contradiction by transforming the static identification system into a dynamic one where the same encryption function serves both reliable decryption and tracking prevention.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of the group user key identifier from a constant value to a variable value that changes with each communication. By changing this critical parameter, the system maintains the encryption functionality (reliability) while preventing identification and tracking of the transmitting client across different sessions, thus resolving the technical contradiction.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If the transmitting client changes the group user key identifier for each communication, then the client cannot be tracked, but the receiving client cannot reliably decrypt the content without the correct identifier

Engineering Contradiction:
Improveclient tracking preventionVSAvoidcontent decryption reliability
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent implements feedback by having the transmitting client send the generated group user key identifier along with the encrypted content to the receiving client. This feedback mechanism ensures that the receiving client receives the correct identifier needed for decryption, maintaining reliability, while the identifier itself remains changing to prevent tracking. The feedback loop resolves the contradiction by coordinating the changing identifier with the decryption capability.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If the network spans multiple security domains, then the network achieves broader coverage and functionality, but receiving clients can identify and link communications across domains compromising security

Engineering Contradiction:
Improvenetwork coverageVSAvoidcross-domain client identification
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies segmentation by treating each communication session as a separate, isolated unit with its own group user key identifier. This segmentation prevents cross-domain identification by ensuring that identifiers generated in one security domain do not leak information about the transmitting client to other domains. Each segment (communication session) maintains independence, allowing broader network coverage while preventing cross-domain tracking.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20230292111A1Method for managing identity by a transmitting entity in a 3GPP MCS network
Publication Date: 2023.09.14 AIRBUS DS SLC
  • US20230292111A1 patent drawing
  • US20230292111A1 patent drawing
  • US20230292111A1 patent drawing

AI summary

A method implemented by a client transmitting entity included in a 3GPP MCS (3rd Generation Partnership Program Mission Critical Services) standard network, the client transmitting entity being configured to transmit a plurality of contents intended for at least one client receiving entity included in the network, the client transmitting entity and the client receiving entity being affiliated with a same communication group, the method including generating, by the client transmitting entity, a group user key identifier, the group user key identifier being specific to the communication group and being used to encrypt the content, the generation being repeated each time a predetermined event takes place.