MBMS Security Key Synchronization for Server Mobility
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing security architecture for multimedia broadcast/multicast services (MBMS) and OMA Broadcast BCAST systems faces challenges with mobility between servers, leading to issues such as MTK_ID consumption discrepancies, service interruptions, and key expiration problems, which result in inefficient key management and potential smart card exhaustion.
Innovation Solution
A method is introduced where user terminal devices proactively trigger new streaming servers to generate new user-specific security keys, receive and generate new security keys, and use them for a previously established streaming service, enabling seamless key updates and synchronization across multiple servers, thus avoiding excessive MTK_ID consumption and ensuring continuous service.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the existing GBA security architecture is used for MBMS services, then user authentication and service key distribution are established, but mobility between MBMS servers causes MTK_ID consumption discrepancies and service interruptions
Solution Approach 1:
The terminal proactively triggers key update procedures before MTK_ID exhaustion occurs by monitoring the MTK_ID counter and initiating new key generation when thresholds are approached. This preliminary action prevents service interruptions caused by key exhaustion during server mobility.
Solution Approach 2:
The system implements feedback mechanisms where the terminal monitors MTK_ID consumption levels and communicates with the network to trigger key refresh procedures. The network responds by providing new keys, creating a closed-loop system that adapts to mobility conditions and prevents service disruption.
2Reliability
If frequent key updates are performed to maintain security during mobility, then service security is improved, but smart card lifespan is reduced due to excessive key generation and storage operations
Solution Approach 1:
Instead of performing full key update cycles frequently, the system performs partial key updates only when necessary - specifically when MTK_ID thresholds are approached or server changes are detected. This reduces unnecessary smart card operations while maintaining adequate security levels.
Solution Approach 2:
The system dynamically adjusts key update parameters based on mobility patterns and MTK_ID consumption rates. By changing the frequency and scope of key updates based on actual conditions rather than using fixed intervals, the system optimizes the balance between security and smart card longevity.
3Adaptability or versatility
If multiple user-specific keys are generated for different servers, then mobility between servers is supported, but key management complexity increases and MTK_ID consumption accelerates
Solution Approach 1:
The system uses a universal key derivation mechanism where a single master key can derive multiple user-specific keys for different servers. This multi-functional approach allows the terminal to support multiple servers without proportionally increasing key management complexity, as the same derivation algorithm serves all servers.
Solution Approach 2:
The key management system is segmented into hierarchical levels - master keys at the network level and derived user-specific keys at the terminal level. This segmentation allows centralized key distribution while distributing the computational burden of key derivation to individual terminals, reducing overall system complexity.
Data Source
Figure 1A
Figure 1B
Figure 2
AI summary
In accordance with the exemplary embodiments of the invention there is at least a method and apparatus to perform operations including triggering by user terminal device a new streaming server to generate new user-specific security keys; receiving at the user terminal device from the new streaming server a new security key specific for the new streaming server; generating at the user terminal device for the streaming server user-specific security keys; and using the new user-specific security keys generated at the user terminal device with the new streaming server for a previously established streaming service.