Multicast Security Key Derivation for Mobile Stations
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security methods do not support multicast communication between a base station and a group of users, lacking the necessary security measures for this type of communication.
Innovation Solution
A method and apparatus that share a multicast authorization key (MAK) to derive a prekey and multicast security key, including a traffic encryption key (MTEK), for encrypting and decrypting multicast traffic, with mechanisms for updating these keys as needed to ensure secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional security methods are used, then unicast communication security is supported, but multicast communication security is not supported
Solution Approach 1:
The patent extends unicast security parameters (UE_KAS, MTK) to multicast context by introducing new parameters (MAK, MTEK) while maintaining the same functional structure. The security model is adapted by changing parameters from unicast-specific to multicast-appropriate values, allowing the existing security framework to support multicast without fundamental redesign
Solution Approach 2:
The patent creates a universal security support mechanism that can handle both unicast and multicast communications. The base station and mobile stations use a unified key management approach where MAK serves as the foundation for deriving MTEK, which then protects multicast traffic similarly to how MTK protects unicast traffic, achieving multi-functional security support
2Reliability
If multicast security keys are updated frequently, then security is maintained, but communication overhead increases
Solution Approach 1:
The patent performs preliminary key derivation by having the base station and mobile stations pre-establish the MAK and prekey before multicast communication begins. This preliminary action allows the actual MTEK to be derived on-demand without requiring frequent key distribution messages, reducing overhead while maintaining security
Solution Approach 2:
Mobile stations autonomously derive their own MTEK from the shared prekey and multicast group identifier without requiring the base station to distribute individual keys. This self-service approach eliminates the need for extensive key distribution messaging while ensuring each station has the necessary security credentials
Data Source
AI summary
A method of supporting a security for a multicast communication is provided in a mobile station. The mobile station shares an MAK with a base station, derives a prekey based on a first parameter including the MAK, and derives a multicast security key including an MTEK based on a second parameter including the prekey, and decrypts a multicast traffic using the multicast security key.


