PC5 Relay Key Management for Secure Remote UE Discovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 5G systems, there is a lack of defined methods for a remote UE to discover and establish secure communication with a UE-to-network relay for both public safety and commercial services, particularly regarding the retrieval of common security keys for PC5 interface discovery and communication.
Innovation Solution
A method is provided where the remote UE and UE-to-network relay utilize associated Application Function nodes (AF-1 and AF-2) in their home PLMN to retrieve discovery and communication keys, enabling secure communication over the PC5 interface by exchanging encrypted messages and using shared algorithms to generate keys based on a relay service code.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the remote UE contacts all PKMFs of potential relays to fetch PRUK while still in coverage, then the remote UE can obtain necessary security keys for relay communication, but the complexity of key management increases and time is lost due to multiple contacts required
Solution Approach 1:
The patent introduces a key distributor as an intermediary entity that receives PRUK from the remote UE's PKMF and distributes it to potential relay UEs. This mediator simplifies the key management process by centralizing the key distribution function, eliminating the need for the remote UE to contact multiple PKMFs directly.
Solution Approach 2:
The patent implements preliminary action by having the remote UE fetch and store PRUK while still in network coverage before actual relay communication is needed. This advance key acquisition ensures that when the UE enters out-of-coverage mode, the security keys are already available, eliminating the need for real-time key fetching during critical communication phases.
2Adaptability or versatility
If the remote UE stores multiple PRUK for different PKMFs, then the remote UE can communicate with any potential relay, but the device complexity and memory requirements increase
Solution Approach 1:
The key distributor acts as a mediator that manages the mapping between PRUK and relay identifiers. Instead of the remote UE storing and managing multiple PRUK itself, the key distributor centralizes this management function, reducing the complexity at the UE side while maintaining the ability to support multiple relays.
Solution Approach 2:
The patent implements a universal key management approach where a single PRUK can serve multiple relay UEs through the key distributor. The key distributor enables one PRUK to be distributed to multiple relays, eliminating the need for the remote UE to store separate PRUK for each relay, thus reducing memory requirements and management complexity.
3Ease of operation
If the remote UE is in out-of-coverage mode, then the remote UE can operate independently from network infrastructure, but the ability to fetch new security keys is lost
Solution Approach 1:
The patent implements preliminary action by requiring the remote UE to fetch and store PRUK while still in network coverage before transitioning to out-of-coverage mode. This advance key acquisition ensures that the UE has sufficient security keys stored to operate independently for an extended period without network access, maintaining both ease of operation and security reliability.
Solution Approach 2:
The patent enables self-service by allowing the remote UE to operate autonomously using previously fetched PRUK when in out-of-coverage mode. The UE can independently derive communication keys from stored PRUK and engage in relay communication without requiring real-time network infrastructure, thus achieving self-sufficient operation.
Data Source
AI summary
A remote communication device can receive a discovery key; receive a communication key and a key identifier, ID, for the communication key; and discover a relay communication device. Discovering the relay communication device can include receiving an encrypted discovery message from the relay communication device and decrypting the encrypted discovery message using the discovery key. The remote communication device can further transmit a direct communication request to the relay communication device responsive to receiving and decrypting the encrypted discovery message from the relay communication device. The direct communication request can include the key ID for the communication key. The remote communication device can further receive an encrypted direct communication response from the relay communication device. Receiving the encrypted direct communication response can include decrypting the encrypted direct communication response.


