PC5 Sidelink Encrypted Message Transmission via Application Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current V2X communication standards lack standardized solutions for mutual authentication and encryption at the network level, making it difficult for small service providers to implement secure communication between vehicles or communication participants, especially in innovative use cases that require confidentiality and anonymity.

Innovation Solution

A method and system for transmitting message content in encrypted form using PC5 sidelink functionality, specifically Mode 4, where client devices execute software client applications communicating with an application server entity, involving registration data for service identification and session key management to facilitate secure communication between vehicles or participants.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If standardized V2X communication standards are used, then network coverage and basic message transmission are improved, but mutual authentication and encryption capabilities are insufficient

Engineering Contradiction:
Improvemessage authentication and encryptionVSAvoidsupport for innovative use cases
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the security functions into two parts: standardized network-level authentication (using existing V2X standards) and application-level encryption (implemented separately by service providers). This allows compliance with standards while enabling customized security for different use cases.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary layer (application server entity) that facilitates secure communication between vehicles. This intermediary manages key exchange and encryption without requiring direct peer-to-peer authentication, enabling secure communication while maintaining network coverage.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If sender anonymity is implemented through pseudonymization, then data protection is improved, but mutual authentication becomes difficult

Engineering Contradiction:
Improvedata protection and anonymityVSAvoidmutual authentication
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent separates authentication and anonymity functions: network-level pseudonymization maintains anonymity while the application-level key exchange mechanism enables mutual authentication. Each layer operates independently to fulfill its specific requirement.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary key exchange and authentication before actual message transmission. By establishing secure channels in advance through the application server entity, the system enables both anonymity during transmission and reliable authentication without conflict.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If application-level security functions are implemented, then customization for specific use cases is improved, but device complexity increases

Engineering Contradiction:
Improvecustomization for specific use casesVSAvoidsecurity implementation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent uses an intermediary application server entity that handles complex security operations (key generation, exchange, and management) centrally. This reduces the complexity burden on individual vehicles while enabling customized security for different use cases.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal security framework where the same application server entity can serve multiple use cases with different security requirements. The standardized interface allows various applications to leverage the same infrastructure without implementing duplicate security mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Speed

If direct peer-to-peer communication is used, then latency is reduced, but key management becomes complex

Engineering Contradiction:
Improvecommunication latencyVSAvoidkey management complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary application server entity that simplifies key management for direct peer-to-peer communication. The server handles key generation and distribution, allowing vehicles to communicate directly with low latency while avoiding the complexity of implementing their own key management systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4199550B1Method for transmitting a message content in encrypted form between a first communication user and at least one second communication user, system, telecommunication network, computer program and computer readable medium
Publication Date: 2024.08.28 DEUTSCHE TELEKOM AG
  • EP4199550B1 patent drawingFigure 1
  • EP4199550B1 patent drawingFigure 2
  • EP4199550B1 patent drawingFigure 3

AI summary

A method for transmitting message content in encrypted form between a first communication participant and at least one second communication participant is described, wherein the transmission of the message content is carried out by means of broadcast messages of a PC5 sidelink functionality, in particular using the Mode 4 functionality, wherein both the first communication participant and the at least one second communication participant are client computer devices for executing software code of a software client application, wherein the software client application of both the first communication participant and the software client application of the at least one second communication participant is configured to communicate with an application server entity, in particular via a telecommunications network.wherein, by means of the software client applications of the communication participants, registration data is sent from the application server entity to the communication participants and/or from the communication participants to the application server entity, so that the communication participants have at least one service identifier information,wherein the method comprises the following procedural steps: -- in a first step, session identifier information is generated by the first communication participant to start a broadcast message session initiated by the first communication participant -- in a second step following the first step, the first communication participant sends a request broadcast message for the participation of the second communication participant in the message session and the first communication participant receives a response message for the participation of the second communication participant in the message session, wherein the request broadcast message and/or the response message is secured, in particular signed, using at least a part of the registration data,-- In a third step following the second step, broadcast messages are transmitted between the first and second communication participants to convey the message content in a secure form.