Group Traffic Encryption Key Updates With Longer GKEK Cycles
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing methods for updating group traffic encryption keys (GTEK) in wireless portable Internet systems, particularly for multicast, broadcast, and multicast-broadcast services, lead to excessive radio resource consumption due to frequent transmissions of Key Update Command messages, especially when the lifetime of the traffic encryption key (TEK) is reduced for enhanced security.
Innovation Solution
The method involves determining whether the current group key encryption key (GKEK) expires within the lifetime of the current GTEK, generating and transmitting new GTEK and GKEK only when necessary, and setting the GKEK lifetime longer than the GTEK lifetime to reduce the frequency of updates and transmissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the lifetime of the traffic encryption key (TEK) is reduced for enhanced service security, then service security is improved, but the number of TEK updates and GKEK updates increases, resulting in increased radio resource consumption
Solution Approach 1:
The patent segments the key management functions by introducing a group key encryption key (GKEK) that is separate from the traffic encryption key (TEK). The GKEK is used to encrypt and manage multiple TEKs, allowing the system to reduce TEK update frequency while maintaining security. This segmentation enables independent management of key encryption (GKEK) and key usage (TEK), resolving the contradiction between security and resource consumption.
2Reliability
If the base station transmits a Key Update Command message for GKEK update to each subscriber station whenever TEK is updated, then all subscriber stations receive updated encryption keys, but the processing amount and radio resource consumption increase
Solution Approach 1:
The patent merges the GKEK update operations for multiple subscriber stations into a single broadcast message. Instead of individually updating each subscriber station's GKEK whenever a TEK changes, the base station transmits one GKEK update message that all subscriber stations can process simultaneously. This combining approach maintains complete key updates while dramatically reducing processing overhead and radio resource usage.
3Ease of operation
If the lifetime of the GKEK is set the same as the TEK lifetime, then key management is simplified, but the frequency of GKEK updates increases, leading to excessive radio resource consumption
Solution Approach 1:
The patent changes the lifetime parameter of the GKEK to be longer than the TEK lifetime. This parameter modification allows the GKEK to remain valid across multiple TEK update cycles, reducing the frequency of GKEK updates. The system maintains operational simplicity by keeping the key hierarchy clear while optimizing resource consumption through extended GKEK validity periods.
Data Source
AI summary
The present invention relates to a method for managing a group traffic encryption key (GTEK) in a wireless portable Internet system. In the method, for higher security of a group traffic service such as a multicast service, a broadcast service, and a multicast-broadcast service (MBS), a base station periodically generates and distributes a GTEK to a subscriber station served with the group traffic service. A lifetime of a group key encryption key (GKEK) used for encrypting a GTEK is set greater than that of the GTEK. That is, the GKEK is updated once while the GTEK is updated several times. According to the present invention, security for the group traffic service is increased while reducing radio resource consumption.


