MCPTT MBMS Subchannel Control Message Integrity Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional MCPTT systems lack protection for 'Unmap Group To Bearer' and 'Map Group To Bearer' messages, which are sensitive and vulnerable to denial of service attacks, as they are not integrity and confidentiality protected.

Innovation Solution

Generating a Multimedia Broadcast and Multicast Service Subchannel Control Key (MSCCK) for unicast messages, applying integrity and confidentiality protection to MBMS subchannel control messages, and sending them in multicast to ensure secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If MBMS subchannel control messages are sent in multicast without protection, then communication efficiency and coverage are improved, but security and reliability deteriorate due to vulnerability to spoofing and denial of service attacks

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidmessage integrity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the MBMS subchannel control messages into protected and unprotected portions, applying integrity protection only to critical control messages while leaving other messages transmitted without protection. This allows selective application of security measures to maintain communication efficiency while protecting critical information.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary protection mechanism (integrity protection layer) between the MBMS subchannel control messages and the multicast transmission channel. This intermediary layer verifies message integrity through authentication tags, preventing spoofing and denial of service attacks while maintaining the efficiency of multicast transmission.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If integrity protection is applied to MBMS subchannel control messages, then security against spoofing attacks is improved, but device complexity and processing overhead increase

Engineering Contradiction:
Improvemessage authenticityVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies integrity protection selectively only to specific MBMS subchannel control messages that require security (such as those containing sensitive group IDs or critical control information), rather than protecting all messages uniformly. This local application of protection reduces processing overhead while maintaining security where most needed.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the protection parameter from full-message protection to selective-field protection, applying integrity checks only to specific critical parameters within MBMS subchannel control messages. This reduces the computational burden of integrity verification while maintaining security for the most sensitive information.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If confidentiality protection is applied to MBMS subchannel control messages, then protection against unauthorized access is improved, but communication speed and processing efficiency decrease

Engineering Contradiction:
ImproveconfidentialityVSAvoidmessage processing speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent segments confidentiality protection application to only those MBMS subchannel control messages containing sensitive information (such as group IDs), while allowing other messages to be transmitted and processed without confidentiality protection. This segmentation maintains processing speed for non-sensitive messages while providing confidentiality where required.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial confidentiality protection rather than comprehensive encryption to all MBMS subchannel control messages. By applying confidentiality measures only to the extent necessary for protecting sensitive information, the system maintains communication speed while providing adequate security for critical data elements.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3533246B1Protection of mission-critical push-to-talk multimedia broadcast and multicast service subchannel control messages
Publication Date: 2021.07.28 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP3533246B1 patent drawingFigure 1
  • EP3533246B1 patent drawingFigure 2A
  • EP3533246B1 patent drawingFigure 2B

AI summary

A Mission-Critical Push-To-Talk (MCPTT) node (410, 510, 600, 800) is connected to a group of user equipments (UEs) (405, 505, 700, 900) served by the MCPTT node. The MCPTT node generates a Multimedia Broadcast and Multicast Service (MBMS) Subchannel Control Key (MSCCK) (S305), sends first messages to the UEs in unicast, wherein the first messages include the generated MSCCK (S310), generates at least one MBMS subchannel control message (S315), applies integrity protection and/or confidentiality protection to the at least one MBMS subchannel control message with the MSCCK (S320), and sends the at least one MBMS subchannel control message in multicast (S325).