Binding KEK to Media Streams via Session Description Linkage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for secure media stream key binding, such as MBMS and OMA POC, face reliability and delay issues in Trunked and Conventional Public Safety services over LTE, particularly due to the need for separate security description documents and non-synchronized coordination with Session Initiation Protocol (SIP) messages.

Innovation Solution

A method where a key-encryption-key (KEK) is bound to secure media streams using a linkage within a session description message, incorporating KeyDomainID and KeyGroupID, allowing for immediate secure communication by conveying traffic keys under the protection of KEK, which can include Uniform Resource Identifiers (URIs) for abstract representation, thus eliminating the need for separate security descriptors and synchronizing key-management and SIP messages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a separate security description document is sent to bind keys and streams together, then key binding is achieved, but call setup delay increases

Engineering Contradiction:
Improvekey binding reliabilityVSAvoidcall setup delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent combines the security description information with the Session Initiation Protocol (SIP) messages into a single transmission unit. Specifically, the security parameters including key binding information are embedded within the SIP session setup messages, eliminating the need for separate security description document transmissions. This merging reduces the number of separate communication steps required during call setup, thereby reducing overall setup delay while maintaining reliable key binding.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent performs key binding information preparation in advance by including it within the SIP session setup messages that are exchanged during the initial session establishment phase. By preparing and transmitting the security description information as part of the preliminary session setup process rather than as a subsequent separate step, the key binding is established concurrently with session initialization, reducing the total time required for call setup.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security description is sent after or along with SDP, then key binding is established, but synchronization complexity increases

Engineering Contradiction:
Improvekey binding establishmentVSAvoidcoordination complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the security description information with the Session Description Protocol (SDP) content by embedding it within the SIP messages that carry SDP. This integration ensures that both the session description and security parameters are transmitted together in a synchronized manner, eliminating the complexity of coordinating separate transmission timings for security descriptions and SDP. The binding information is included as part of the same message stream, simplifying the coordination mechanism.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If IP address and port information is included in security description, then stream binding is enabled, but information transmission overhead increases

Engineering Contradiction:
Improvestream binding capabilityVSAvoidmessage size
Core Design Contradiction:
Ease of operationVSQuantity of substance

Solution Approach 1:

The patent leverages the existing SIP message structure which already contains session description information including media stream parameters. By embedding the security description within this multi-functional SIP message that already carries session and media information, the IP address and port data are transmitted as part of the universal session setup protocol rather than as separate dedicated fields. This approach enables stream binding capability while minimizing additional overhead by utilizing the existing message framework.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2649770B1Binding keys to secure media streams
Publication Date: 2016.02.24 MOTOROLA SOLUTIONS INC
  • EP2649770B1 patent drawingFigure 1
  • EP2649770B1 patent drawingFigure 2
  • EP2649770B1 patent drawingFigure 3

AI summary

A key message can include a key-encryption-key (KEK) associated with a KeyDomainID and a KeyGroupID. A session description message can describe streaming media initialization parameters containing media stream information for one or more media streams. For each media stream, the media stream information can include an IP address and a data port. The session description message can further contain a linkage for binding the KEK to a corresponding one of the media streams. The linkage can include the KeyDomainID and KeyGroupID or can include an abstract representation of the KeyDomainID and KeyGroupID. During session initialization, the key-encryption-key (KEK) can be bound to the media streams using the linkage of the session description message. Each of the media streams can be secured using a traffic key conveyed to user equipment (UE) under protection of the key-encryption-key (KEK).