Group Key Distribution for M2M Spoofing Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current machine-to-machine (M2M) communication systems lack secure methods for group message transmission, leading to potential spoofing issues in MTC device management and control.

Innovation Solution

A method is introduced where a unique group key is generated and distributed to MTC devices within a group using the MME, utilizing non-access stratum (NAS) security mode commands or protocol configuration options, ensuring encrypted communication between MTC servers and devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If group messages are broadcasted to MTC devices in an insecure manner, then communication simplicity is maintained, but security and reliability deteriorate due to spoofing vulnerabilities

Engineering Contradiction:
Improvesecurity of group communicationVSAvoidcomplexity of security management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security management approach by introducing distinct security modes (secure broadcast mode and secure unicast mode) and separate key management mechanisms. Group messages are segmented into those requiring broadcast delivery and those requiring unicast delivery, each with appropriate security measures. This segmentation allows security to be applied where needed without complicating the entire communication system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary security mechanism involving group context information and security parameters stored in the MME and eNodeB. These intermediaries mediate between the MTC server and MTC devices, providing secure key distribution and verification without requiring direct complex security management between all parties. The group context acts as a trusted intermediary that facilitates secure communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If individual security management is applied to each MTC device, then security is enhanced, but signalling overhead and network congestion increase

Engineering Contradiction:
Improvesecurity of device communicationVSAvoidsignalling overhead
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges security management for multiple MTC devices into a unified group-level approach. Group context information, including security parameters and keys, is managed at the group level rather than individually for each device. This merging reduces signalling overhead by eliminating redundant security setup procedures while maintaining security through group-wide key distribution and verification mechanisms.

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If group messages are transmitted without encryption, then communication efficiency is maintained, but information security deteriorates due to potential message spoofing

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidspoofing of group messages
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the security parameter of group message transmission by introducing encryption options based on the secure broadcast mode. Messages can be transmitted with appropriate security parameters (encryption keys, integrity protection) applied selectively. This parameter change enables encrypted group communication that maintains efficiency while protecting against spoofing, as the security parameters are applied at the protocol level without requiring individual device-by-device encryption.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2578007B1Securing group communication in a machine-to-machine communication environment
Publication Date: 2020.04.15 SAMSUNG ELECTRONICS CO LTD
  • EP2578007B1 patent drawingFigure 1
  • EP2578007B1 patent drawingFigure 2
  • EP2578007B1 patent drawingFigure 3A

AI summary

The present invention provides a method and system for securing group communication in a machine-to-machine communication environment. In one embodiment, a non-access stratum attach request message is received from a MTC device associated with a MTC group. The MTC device is then authenticated based on subscription data associated with the MTC device. Accordingly, a unique group key is generated for securing group communication with the MTC device associated with a MTC group in a M2M communication environment. The unique group key information is then securely provided to the MTC device and to an associated enhanced node B. The unique group key information may include a unique group key, an index value associated with the unique group key, selected security algorithm, and key validity period. Based on the unique group key information, broadcast group messages are securely communicated between a MTC server or a network entity and the MTC device.