Direct Communication Key Establishment via GBA Bootstrapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Pre-configuring shared keys for ProSe Direct Communication between User Equipment devices and UE-to-Network Relays is complex due to the need to cover various devices and network scenarios, including different Home PLMNs and roaming scenarios, making it challenging to establish secure communication without pre-configuration.
Innovation Solution
The method involves using the Generic Bootstrapping Architecture (GBA) to establish a UE shared key with a Bootstrapping Server Function, deriving a transaction identifier, and then using this identifier along with a Direct Communication Element identifier to derive a direct communication key, allowing secure communication without pre-configuration across different network environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If pre-configured shared keys are used for ProSe Direct Communication, then secure communication between devices is achieved, but the complexity of key management increases significantly across multiple devices and network scenarios
Solution Approach 1:
The patent introduces a key management server as an intermediary entity that centralizes the generation, distribution, and management of shared keys. Instead of each device pre-configuring keys with every other device, the key management server acts as a mediator that dynamically provides appropriate keys based on device identities and network context, thereby reducing key management complexity while maintaining security.
Solution Approach 2:
The system performs preliminary key generation and storage at the key management server before actual communication occurs. Keys are pre-computed based on device identities and stored securely at the server, so when communication is needed, the keys are already prepared and can be quickly retrieved or derived, eliminating the need for complex real-time key negotiation between devices.
2Adaptability or versatility
If pre-configured shared keys are used for all possible communication paths, then all devices can communicate securely, but the number of keys that must be pre-configured becomes extremely large
Solution Approach 1:
The patent implements a universal key management system where a single key management server serves multiple devices and network scenarios. The server can generate and manage keys for device-to-device communication, device-to-network relay communication, and communication across different PLMNs using a unified approach, eliminating the need for separate key configurations for each communication path.
Solution Approach 2:
The system uses identity parameters (device identifiers, PLMN identifiers) as inputs to key derivation functions. By changing the input parameters based on the specific communication scenario, the same key management mechanism can generate appropriate keys dynamically, rather than requiring separate pre-configured keys for each scenario.
3Adaptability or versatility
If devices roam into new PLMNs or use different Home PLMNs, then network flexibility is improved, but the ability to establish secure communication becomes more difficult
Solution Approach 1:
The patent separates the key management function from the communication function. The key management server handles identity verification and key generation independently of the actual communication path. This segmentation allows devices to roam between PLMNs and use different network relays while the key management system continues to provide secure keys based on device identities, not network location.
Solution Approach 2:
The key management server acts as a trusted intermediary that verifies device identities and provides appropriate keys regardless of which PLMN the device is currently connected to. This intermediary approach ensures that secure communication can be established even when devices roam, as the key management system is not tied to any specific network operator.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Methods (100, 200, 300) and apparatus (400, 500, 600, 700, 800, 900) are disclosed for establishing a key for direct communication between a User Equipment device, UE, and a device. The methods and apparatus cooperate to form a system for securing direct communication between a UE and a device over an interface. The system comprises a UE (20), a device (30) and a Direct Communication Element (40). The UE (20) is configured to establish a UE shared key with a Bootstrapping Server Function, BSF (50), using a Generic Bootstrapping Architecture, GBA, procedure, to discover the device (30) through a discovery procedure after establishing the UE shared key, and to derive a direct communication key from at least the UE shared key. The device (30) is configured to receive a transaction identifier associated with the UE shared key from the UE (20), to send the transaction identifier to the Direct Communication Element (40), and to receive the direct communication key from the Direct Communication Element (40). The Direct Communication Element (40) is configured to receive the transaction identifier from the device (30), to obtain a shared session key from the BSF (50); to derive the direct communication key, and to send the direct communication key to the device (30). Also disclosed are a computer product operable to carry out methods according to the present invention and a computer program product comprising a computer readable medium having such a computer product stored thereon.