Off-Network Key Management for Mission Critical Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In off-network communications, the requirement for pre-establishing security context using key information restricts service scenarios where user equipment (UE) initiates services directly or moves off-network without sharing key information, limiting the use of one-to-one Mission Critical Data (MCD) communication services.
Innovation Solution
A method and apparatus for off-network key management in one-to-one MCD communication, where an originating MCD client device initiates a request for a short data service message, determines if a valid private call key (PCK) is available, and either generates and transmits the PCK and PCK-ID or uses an existing PCK, encapsulating them in a MIKEY-SAKKE I_MESSAGE for secure key sharing with the terminating MCD client device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If pre-established key information sharing is required for off-network communication, then security context is established, but service scenarios are restricted and UE cannot initiate services directly in off-network
Solution Approach 1:
The patent applies preliminary action by pre-configuring root certificates and public key infrastructure in the UE before off-network communication. This allows the UE to perform key derivation and security context establishment autonomously when needed, without requiring pre-shared keys or network presence during service initiation.
Solution Approach 2:
The patent introduces a certificate authority (CA) as an intermediary that issues certificates to both the network and UEs. This CA-mediated trust model replaces direct pre-shared key requirements, allowing UEs to verify network authenticity and establish security contexts independently in off-network scenarios.
2Reliability
If key information must be shared before UE moves to off-network, then security is maintained, but UE cannot initiate services or move off-network without pre-shared keys
Solution Approach 1:
The patent enables self-service by allowing the UE to autonomously derive session keys and establish security contexts using pre-configured root certificates and public key infrastructure. The UE performs key derivation, certificate verification, and security parameter negotiation independently without requiring pre-shared keys or network assistance during off-network service initiation.
3Reliability
If pre-established security context is used, then off-network communication security is ensured, but service scenarios where UE initiates directly in off-network are restricted
Solution Approach 1:
The patent changes the security model parameters from pre-shared symmetric keys to public key infrastructure with certificate-based authentication. This parameter change enables the UE to initiate off-network services directly by performing asymmetric key exchange and deriving symmetric session keys dynamically, rather than relying on pre-configured shared secrets.
Data Source
AI summary
Provided are methods and apparatuses for off-network key management in one-to-one mission critical data communication. A method includes initiating an off-network MCData service for the communication with an other client device, obtaining a MCData message including a MCdata protection key and an identifier of the MCdata protection key, in case that a valid MCdata protection key for the other client device is not available, and transmitting the MCData message to the other client device.


