Key Negotiation Processing for Proximity Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In proximity communication scenarios, existing technologies face challenges in securely negotiating keys between User Equipments (UEs) for establishing a secure communication channel, which is essential for confidentiality and integrity protection against potential eavesdropping and tampering.

Innovation Solution

A key negotiation processing method and apparatus where a control network element acquires and sends key negotiation parameters to UEs, allowing them to generate a shared key for secure communication, ensuring reliability and efficiency by controlling the key negotiation process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If UEs perform key negotiation directly without operator network involvement, then communication efficiency is improved, but key negotiation reliability and security are worsened

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidkey negotiation reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a control network element (MME) as an intermediary to facilitate key negotiation between UEs. The MME receives key negotiation parameters from both UEs, calculates shared key negotiation parameters using stored shared keys, and exchanges these parameters with the UEs to generate the final communication key. This mediator approach ensures reliable key negotiation while maintaining UE-to-UE communication efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If UEs perform key negotiation without operator network control, then device complexity is reduced, but key negotiation security is worsened

Engineering Contradiction:
Improvekey negotiation complexityVSAvoideavesdropping and tampering
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The control network element acts as a security intermediary that receives key negotiation parameters from UEs, validates them against stored shared keys, and facilitates secure key generation. This intermediary approach enhances security against eavesdropping and tampering while keeping the UE-side implementation relatively simple.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary action by pre-storing shared keys between the control network element and each UE before key negotiation is needed. During key negotiation, the control network element uses these pre-existing shared keys to calculate shared key negotiation parameters, ensuring secure key generation without requiring complex real-time authentication procedures at the UE.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If control network element performs key negotiation calculation, then key negotiation security is improved, but network overhead is worsened

Engineering Contradiction:
Improvecommunication securityVSAvoidnetwork overhead
Core Design Contradiction:
Object-affected harmful factorsVSLoss of energy

Solution Approach 1:

The control network element serves as an intermediary that performs key negotiation calculations using pre-stored shared keys. This approach enhances security by centralizing the complex cryptographic operations while minimizing the data exchange volume between UEs, as only key negotiation parameters need to be transmitted rather than full cryptographic sessions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3054622B1Method and device for key negotiation processing
Publication Date: 2019.08.28 HUAWEI TECH CO LTD
  • EP3054622B1 patent drawingFigure 1
  • EP3054622B1 patent drawingFigure 2
  • EP3054622B1 patent drawingFigure 3~4

AI summary

Embodiments of the present invention provide a key negotiation processing method and apparatus. The key negotiation processing method includes: acquiring, by a control network element, a first key negotiation parameter and a second key negotiation parameter; and sending, by the control network element, the first key negotiation parameter and/or the second key negotiation parameter to the first user equipment UE and a second UE, so that the first UE and the second UE generate a key according to the first key negotiation parameter and the second key negotiation parameter. According to the embodiments of the present invention, key negotiation may be performed between two UEs that perform proximity communication.