MBS Key Distribution for Secure 5G Multicast Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication systems face challenges in securely distributing keys for multicast/broadcast services (MBS) traffic, particularly in 5G networks, to ensure confidentiality, integrity, and anti-replay protection, as well as managing key distribution and authorization for UEs accessing multicast communication services.

Innovation Solution

The proposed solution involves distributing unique or common security keys for UEs through the MB-SMF, using symmetric or asymmetric cryptography, to encrypt and decrypt MBS packets in both point-to-point (PTP) and point-to-multipoint (PTM) delivery methods, ensuring secure key management and encryption for MBS traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If unique keys are distributed to each UE for MBS traffic, then security and confidentiality are improved, but key management complexity and overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments key management into two distinct approaches: unique keys for PTP delivery to ensure individual security, and common keys for PTM delivery to simplify group management. This segmentation allows the system to optimize security without uniformly increasing complexity across all delivery scenarios.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different key distribution strategies based on the specific delivery method requirements. PTP uses unique keys per UE where maximum security is critical, while PTM uses common keys where efficiency and simplicity are prioritized. This local differentiation resolves the contradiction by tailoring key management to local needs rather than applying a uniform approach.

Inventive Principle:
Principle #3Local quality

2Device complexity

If common keys are used for multiple UEs, then key management is simplified, but security and confidentiality deteriorate

Engineering Contradiction:
Improvekey management simplicityVSAvoidconfidentiality
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent applies common keys specifically for PTM delivery scenarios where multiple UEs need to access the same content, accepting reduced confidentiality as a trade-off for simplified management. Conversely, unique keys are applied for PTP delivery where individual confidentiality is required. This localized application of key strategies resolves the contradiction by matching key type to delivery scenario requirements.

Inventive Principle:
Principle #3Local quality

3Reliability

If encryption is applied to all MBS packets, then confidentiality and integrity are improved, but processing overhead and latency increase

Engineering Contradiction:
ImproveintegrityVSAvoidprocessing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies encryption selectively based on the delivery method and security requirements. PTP packets receive encryption for maximum security, while PTM packets use common key encryption only where needed. This localized encryption approach maintains integrity where critical while reducing unnecessary processing overhead elsewhere.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP4238325B1MBS-key distribution and traffic protection
Publication Date: 2025.07.23 APPLE INC
  • EP4238325B1 patent drawingFigure 1
  • EP4238325B1 patent drawingFigure 2
  • EP4238325B1 patent drawingFigure 3

AI summary

MBS key distribution includes processing group information associated with an MB session context received from an AF. At least a portion of the group information comprises a TMGI. A plurality of session join requests received from a plurality of UEs are processed. Each of the plurality of session join requests include the TMGI and are associated with the MB session context. A request associated with the MB session context for transmission to an MB-SMF is encoded. A response associated with the MB session context received from the MB-SMF is processed. The response includes a key derived for each of a portion of the plurality of UEs using a UE ID and the TMGI. A DL NAS message and an N2 message are encoded for the plurality of UEs and a base station, respectively. The DL NAS message and the N2 message include the derived key.