Direct Communication Key Establishment via GBA Bootstrapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Pre-configuring shared keys for ProSe Direct Communication between User Equipment devices and UE-to-Network Relays is complex due to the need to cover various devices and network scenarios, including different Home PLMNs and roaming scenarios, making it challenging to establish secure communication without pre-configuration.

Innovation Solution

The method involves using the Generic Bootstrapping Architecture (GBA) to establish a UE shared key with a Bootstrapping Server Function, deriving a transaction identifier, and then using this identifier along with a Direct Communication Element identifier to derive a direct communication key, allowing secure communication without pre-configuration across different network environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If pre-configured shared keys are used for ProSe Direct Communication, then secure communication between devices is achieved, but the complexity of key management increases significantly across multiple devices and network scenarios

Engineering Contradiction:
Improvesecure communicationVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a key management server as an intermediary entity that centralizes the generation, distribution, and management of shared keys. Instead of each device pre-configuring keys with every other device, the key management server acts as a mediator that dynamically provides appropriate keys based on device identities and network context, thereby reducing key management complexity while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary key generation and storage at the key management server before actual communication occurs. Keys are pre-computed based on device identities and stored securely at the server, so when communication is needed, the keys are already prepared and can be quickly retrieved or derived, eliminating the need for complex real-time key negotiation between devices.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If pre-configured shared keys are used for all possible communication paths, then all devices can communicate securely, but the number of keys that must be pre-configured becomes extremely large

Engineering Contradiction:
Improvecommunication coverageVSAvoidnumber of keys
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent implements a universal key management system where a single key management server serves multiple devices and network scenarios. The server can generate and manage keys for device-to-device communication, device-to-network relay communication, and communication across different PLMNs using a unified approach, eliminating the need for separate key configurations for each communication path.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses identity parameters (device identifiers, PLMN identifiers) as inputs to key derivation functions. By changing the input parameters based on the specific communication scenario, the same key management mechanism can generate appropriate keys dynamically, rather than requiring separate pre-configured keys for each scenario.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If devices roam into new PLMNs or use different Home PLMNs, then network flexibility is improved, but the ability to establish secure communication becomes more difficult

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidsecure communication establishment
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent separates the key management function from the communication function. The key management server handles identity verification and key generation independently of the actual communication path. This segmentation allows devices to roam between PLMNs and use different network relays while the key management system continues to provide secure keys based on device identities, not network location.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The key management server acts as a trusted intermediary that verifies device identities and provides appropriate keys regardless of which PLMN the device is currently connected to. This intermediary approach ensures that secure communication can be established even when devices roam, as the key management system is not tied to any specific network operator.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3248404B1Method and apparatus for direct communication key establishment
Publication Date: 2020.07.22 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP3248404B1 patent drawingFigure 1
  • EP3248404B1 patent drawingFigure 2
  • EP3248404B1 patent drawingFigure 3

AI summary

Methods (100, 200, 300) and apparatus (400, 500, 600, 700, 800, 900) are disclosed for establishing a key for direct communication between a User Equipment device, UE, and a device. The methods and apparatus cooperate to form a system for securing direct communication between a UE and a device over an interface. The system comprises a UE (20), a device (30) and a Direct Communication Element (40). The UE (20) is configured to establish a UE shared key with a Bootstrapping Server Function, BSF (50), using a Generic Bootstrapping Architecture, GBA, procedure, to discover the device (30) through a discovery procedure after establishing the UE shared key, and to derive a direct communication key from at least the UE shared key. The device (30) is configured to receive a transaction identifier associated with the UE shared key from the UE (20), to send the transaction identifier to the Direct Communication Element (40), and to receive the direct communication key from the Direct Communication Element (40). The Direct Communication Element (40) is configured to receive the transaction identifier from the device (30), to obtain a shared session key from the BSF (50); to derive the direct communication key, and to send the direct communication key to the device (30). Also disclosed are a computer product operable to carry out methods according to the present invention and a computer program product comprising a computer readable medium having such a computer product stored thereon.