Off-Network Key Management for Mission Critical Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In off-network communications, the requirement for pre-establishing security context using key information restricts service scenarios where user equipment (UE) initiates services directly or moves off-network without sharing key information, limiting the use of one-to-one Mission Critical Data (MCD) communication services.

Innovation Solution

A method and apparatus for off-network key management in one-to-one MCD communication, where an originating MCD client device initiates a request for a short data service message, determines if a valid private call key (PCK) is available, and either generates and transmits the PCK and PCK-ID or uses an existing PCK, encapsulating them in a MIKEY-SAKKE I_MESSAGE for secure key sharing with the terminating MCD client device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If pre-established key information sharing is required for off-network communication, then security context is established, but service scenarios are restricted and UE cannot initiate services directly in off-network

Engineering Contradiction:
Improvesecurity context establishmentVSAvoidservice scenario flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by pre-configuring root certificates and public key infrastructure in the UE before off-network communication. This allows the UE to perform key derivation and security context establishment autonomously when needed, without requiring pre-shared keys or network presence during service initiation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a certificate authority (CA) as an intermediary that issues certificates to both the network and UEs. This CA-mediated trust model replaces direct pre-shared key requirements, allowing UEs to verify network authenticity and establish security contexts independently in off-network scenarios.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If key information must be shared before UE moves to off-network, then security is maintained, but UE cannot initiate services or move off-network without pre-shared keys

Engineering Contradiction:
Improvesecurity context availabilityVSAvoidservice initiation capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables self-service by allowing the UE to autonomously derive session keys and establish security contexts using pre-configured root certificates and public key infrastructure. The UE performs key derivation, certificate verification, and security parameter negotiation independently without requiring pre-shared keys or network assistance during off-network service initiation.

Inventive Principle:
Principle #25Self-service

3Reliability

If pre-established security context is used, then off-network communication security is ensured, but service scenarios where UE initiates directly in off-network are restricted

Engineering Contradiction:
Improveoff-network communication securityVSAvoidoff-network service initiation flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent changes the security model parameters from pre-shared symmetric keys to public key infrastructure with certificate-based authentication. This parameter change enables the UE to initiate off-network services directly by performing asymmetric key exchange and deriving symmetric session keys dynamically, rather than relying on pre-configured shared secrets.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12095915B2Method and apparatus for key management in mission critical data communication
Publication Date: 2024.09.17 SAMSUNG ELECTRONICS CO LTD
  • US12095915B2 patent drawing
  • US12095915B2 patent drawing
  • US12095915B2 patent drawing

AI summary

Provided are methods and apparatuses for off-network key management in one-to-one mission critical data communication. A method includes initiating an off-network MCData service for the communication with an other client device, obtaining a MCData message including a MCdata protection key and an identifier of the MCdata protection key, in case that a valid MCdata protection key for the other client device is not available, and transmitting the MCData message to the other client device.