Binding KEK to Media Streams via Session Description Linkage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for secure media stream key binding, such as MBMS and OMA POC, face reliability and delay issues in Trunked and Conventional Public Safety services over LTE, particularly due to the need for separate security description documents and non-synchronized coordination with Session Initiation Protocol (SIP) messages.
Innovation Solution
A method where a key-encryption-key (KEK) is bound to secure media streams using a linkage within a session description message, incorporating KeyDomainID and KeyGroupID, allowing for immediate secure communication by conveying traffic keys under the protection of KEK, which can include Uniform Resource Identifiers (URIs) for abstract representation, thus eliminating the need for separate security descriptors and synchronizing key-management and SIP messages.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a separate security description document is sent to bind keys and streams together, then key binding is achieved, but call setup delay increases
Solution Approach 1:
The patent combines the security description information with the Session Initiation Protocol (SIP) messages into a single transmission unit. Specifically, the security parameters including key binding information are embedded within the SIP session setup messages, eliminating the need for separate security description document transmissions. This merging reduces the number of separate communication steps required during call setup, thereby reducing overall setup delay while maintaining reliable key binding.
Solution Approach 2:
The patent performs key binding information preparation in advance by including it within the SIP session setup messages that are exchanged during the initial session establishment phase. By preparing and transmitting the security description information as part of the preliminary session setup process rather than as a subsequent separate step, the key binding is established concurrently with session initialization, reducing the total time required for call setup.
2Reliability
If security description is sent after or along with SDP, then key binding is established, but synchronization complexity increases
Solution Approach 1:
The patent merges the security description information with the Session Description Protocol (SDP) content by embedding it within the SIP messages that carry SDP. This integration ensures that both the session description and security parameters are transmitted together in a synchronized manner, eliminating the complexity of coordinating separate transmission timings for security descriptions and SDP. The binding information is included as part of the same message stream, simplifying the coordination mechanism.
3Ease of operation
If IP address and port information is included in security description, then stream binding is enabled, but information transmission overhead increases
Solution Approach 1:
The patent leverages the existing SIP message structure which already contains session description information including media stream parameters. By embedding the security description within this multi-functional SIP message that already carries session and media information, the IP address and port data are transmitted as part of the universal session setup protocol rather than as separate dedicated fields. This approach enables stream binding capability while minimizing additional overhead by utilizing the existing message framework.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A key message can include a key-encryption-key (KEK) associated with a KeyDomainID and a KeyGroupID. A session description message can describe streaming media initialization parameters containing media stream information for one or more media streams. For each media stream, the media stream information can include an IP address and a data port. The session description message can further contain a linkage for binding the KEK to a corresponding one of the media streams. The linkage can include the KeyDomainID and KeyGroupID or can include an abstract representation of the KeyDomainID and KeyGroupID. During session initialization, the key-encryption-key (KEK) can be bound to the media streams using the linkage of the session description message. Each of the media streams can be secured using a traffic key conveyed to user equipment (UE) under protection of the key-encryption-key (KEK).