Group Security Configuration for Scalable D2D Key Establishment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security techniques for device-to-device (D2D) communications in wireless systems face scalability issues and inefficiencies in energy and message exchanges, particularly as the size of the group increases, and are not effective in managing security when devices change their connection status or become compromised.

Innovation Solution

A managing device creates and distributes a group security configuration to each device in the group, comprising a group-specific and device-specific security parameter, allowing devices to establish secure connections directly without additional communication with the managing device, even when it is offline, and updates these configurations based on changes in device connection status or security compromises.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current link security techniques are used for D2D communications, then security can be established between devices, but the system does not scale efficiently as the group size increases and requires excessive energy and message exchanges

Engineering Contradiction:
Improvesecurity establishmentVSAvoidscalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The security configuration is segmented into two distinct components: a group-specific security parameter shared by all devices in the group, and a device-specific security parameter unique to each individual device. This segmentation allows devices to establish secure connections efficiently without requiring extensive communication with the managing device, as each device independently possesses both the group parameter and its own device-specific parameter for direct key establishment with any other group member.

Inventive Principle:
Principle #1Segmentation

2Reliability

If current link security techniques are used for D2D communications, then security can be established between devices, but excessive energy and message exchanges are required to secure the link

Engineering Contradiction:
Improvesecurity establishmentVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The managing device performs preliminary action by pre-distributing both the group-specific security parameter and each device's device-specific security parameter to all group members during an initial setup phase. This preliminary distribution eliminates the need for extensive real-time message exchanges and energy-consuming authentication protocols when devices need to establish secure connections, as all necessary security materials are already in place.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If a managing device is required for security establishment, then centralized control is achieved, but the system cannot maintain security when the managing device is unavailable or offline

Engineering Contradiction:
Improvecentralized managementVSAvoidsecurity availability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Each device is equipped with local security capabilities through the distribution of both group-specific and device-specific security parameters. This local quality enables devices to independently establish secure connections with any other group member without requiring real-time communication with the managing device. The managing device maintains centralized control for initial configuration and parameter distribution, but individual devices possess the autonomy to maintain security operations independently when needed.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10986175B2Key establishment for communications within a group
Publication Date: 2021.04.20 QUALCOMM INC
  • US10986175B2 patent drawing
  • US10986175B2 patent drawing
  • US10986175B2 patent drawing

AI summary

Methods, systems, and devices for wireless communication are described. A managing device may create a group security configuration for each device of a group of devices managed by the managing device. The group security configuration may include a group security parameter associated with the group of devices and a device-specific security parameter associated with each device in the group of devices. The managing device may provide the group security configuration to one or more devices of the group of devices. The one or more devices may use the group security configuration to directly establish a secure connection for communications between the one or more devices, which may include an establishment of the secure connection without further communications with the managing device during the establishment.