MBMS Security Key Synchronization for Server Mobility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing security architecture for multimedia broadcast/multicast services (MBMS) and OMA Broadcast BCAST systems faces challenges with mobility between servers, leading to issues such as MTK_ID consumption discrepancies, service interruptions, and key expiration problems, which result in inefficient key management and potential smart card exhaustion.

Innovation Solution

A method is introduced where user terminal devices proactively trigger new streaming servers to generate new user-specific security keys, receive and generate new security keys, and use them for a previously established streaming service, enabling seamless key updates and synchronization across multiple servers, thus avoiding excessive MTK_ID consumption and ensuring continuous service.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the existing GBA security architecture is used for MBMS services, then user authentication and service key distribution are established, but mobility between MBMS servers causes MTK_ID consumption discrepancies and service interruptions

Engineering Contradiction:
Improveservice continuityVSAvoidserver mobility support
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The terminal proactively triggers key update procedures before MTK_ID exhaustion occurs by monitoring the MTK_ID counter and initiating new key generation when thresholds are approached. This preliminary action prevents service interruptions caused by key exhaustion during server mobility.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where the terminal monitors MTK_ID consumption levels and communicates with the network to trigger key refresh procedures. The network responds by providing new keys, creating a closed-loop system that adapts to mobility conditions and prevents service disruption.

Inventive Principle:
Principle #23Feedback

2Reliability

If frequent key updates are performed to maintain security during mobility, then service security is improved, but smart card lifespan is reduced due to excessive key generation and storage operations

Engineering Contradiction:
ImprovesecurityVSAvoidsmart card lifespan
Core Design Contradiction:
ReliabilityVSDuration of action of moving object

Solution Approach 1:

Instead of performing full key update cycles frequently, the system performs partial key updates only when necessary - specifically when MTK_ID thresholds are approached or server changes are detected. This reduces unnecessary smart card operations while maintaining adequate security levels.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system dynamically adjusts key update parameters based on mobility patterns and MTK_ID consumption rates. By changing the frequency and scope of key updates based on actual conditions rather than using fixed intervals, the system optimizes the balance between security and smart card longevity.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If multiple user-specific keys are generated for different servers, then mobility between servers is supported, but key management complexity increases and MTK_ID consumption accelerates

Engineering Contradiction:
Improvemulti-server supportVSAvoidkey management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system uses a universal key derivation mechanism where a single master key can derive multiple user-specific keys for different servers. This multi-functional approach allows the terminal to support multiple servers without proportionally increasing key management complexity, as the same derivation algorithm serves all servers.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The key management system is segmented into hierarchical levels - master keys at the network level and derived user-specific keys at the terminal level. This segmentation allows centralized key distribution while distributing the computational burden of key derivation to individual terminals, reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2896155B1Security for mobility between MBMS servers
Publication Date: 2018.04.11 NOKIA TECHNOLOGIES OY
  • EP2896155B1 patent drawingFigure 1A
  • EP2896155B1 patent drawingFigure 1B
  • EP2896155B1 patent drawingFigure 2

AI summary

In accordance with the exemplary embodiments of the invention there is at least a method and apparatus to perform operations including triggering by user terminal device a new streaming server to generate new user-specific security keys; receiving at the user terminal device from the new streaming server a new security key specific for the new streaming server; generating at the user terminal device for the streaming server user-specific security keys; and using the new user-specific security keys generated at the user terminal device with the new streaming server for a previously established streaming service.