Multicast Encryption Key Distribution via Group Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 5G Multicast Broadcast Services (5MBS) face challenges in efficiently updating cryptographic keys to ensure security and reduce signaling overhead, particularly in scenarios where a terminal is compromised or revoked, leading to potential unauthorized access or injection of fake content.
Innovation Solution
A method for a primary station to determine if a group key needs updating and transmit an updated cryptographic key to secondary stations through encrypted messages, using a user-specific encryption key for unicast or set keys for multicast, reducing the number of messages required and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If individual unicast messages are sent to each secondary station to update the group key, then security is maintained, but signaling overhead increases
Solution Approach 1:
The patent segments secondary stations into multiple groups, where each group shares a common group key. When a key update is needed, the system only needs to send unicast messages to the specific group that requires updating, rather than to every individual secondary station. This segmentation reduces signaling overhead while maintaining security by limiting the scope of key distribution to only affected groups.
Solution Approach 2:
The patent uses multicast messages to copy and distribute the updated group key to all secondary stations within a group simultaneously. Instead of sending individual copies to each station via unicast, the system creates one multicast message that is received by all members of the group, significantly reducing the number of messages required while ensuring all stations receive the same security update.
2Reliability
If the group key is updated frequently to prevent unauthorized access, then security is improved, but system complexity increases
Solution Approach 1:
The patent establishes group keys in advance for each group of secondary stations, before any security incidents occur. These preliminary group keys are used to encrypt multicast messages containing key update instructions. By having pre-configured group keys, the system can rapidly respond to security events without needing to establish new encryption mechanisms during the update process, thereby reducing complexity while enabling frequent key updates.
Solution Approach 2:
The patent introduces group keys as intermediary encryption layers between the primary station and individual secondary stations. Instead of managing individual keys for each station or using complex hierarchical key structures, the system uses group keys as mediators that simplify key management. The primary station encrypts messages with the appropriate group key, and all members of that group can decrypt them, reducing overall system complexity while maintaining security.
3Reliability
If individual keys are assigned to each secondary station, then security is enhanced, but key management complexity increases
Solution Approach 1:
The patent merges multiple individual secondary stations into groups, where each group shares a common group key. This merging reduces key management complexity by replacing numerous individual key relationships with fewer group-level key relationships. The primary station only needs to manage and distribute group keys rather than individual keys for each station, significantly simplifying key management while maintaining security through group-based access control.
Solution Approach 2:
The patent makes group keys universal for all secondary stations within a group, allowing a single key to serve multiple functions and multiple stations. Instead of requiring unique keys for each station, the same group key is used by all members of the group for encrypting and decrypting multicast messages. This universality simplifies key distribution and management while maintaining security through the principle of least privilege - each group key only protects its specific group's communications.
Data Source
AI summary
The present invention relates to a method for a primary station distributing an encryption key to a plurality of secondary stations. The method comprises the steps of determining whether a group key needs to be updated, said group key being used for multicast encrypted communication from the primary station to the plurality of secondary stations, upon determining that an update is required, transmit to at least one first subset of the secondary stations through an encrypted unicast message a first set key by uni-cast, transmitting in a multicast message to the first set of the secondary stations an updated group key, said multicast message being encrypted by means of the first set key, or alternatively including said updated group key in the encrypted unicast message carrying the first step key, transmitting in respective multicast messages to further respective sets of secondary station the updated group key, said multicast messages being encrypted by means of respective set keys associated with each corresponding set.


