ProSe Anchor Key Generation for Wireless Relay Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Extending the existing authentication and security framework to handle ProSe relaying poses challenges, including the need to generate security keys for primary authentication of remote communication devices, which impacts key handling at the network-side and device-side.

Innovation Solution

Authenticating remote communication devices for ProSe independently from primary authentication, by generating an anchor key directly from keys included in an authentication vector, rather than from a home network root key, and caching this anchor key for efficient reuse.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the existing authentication framework is extended to handle ProSe relaying by generating security keys from home network root key, then authentication capability for ProSe is improved, but key handling complexity and dependencies on other features increase

Engineering Contradiction:
Improveauthentication capabilityVSAvoidkey handling complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication framework is segmented into two independent paths: one for primary authentication using home network root key, and another for ProSe authentication using access authentication key. This segmentation allows ProSe relaying to be supported without extending the existing primary authentication framework, thereby avoiding increased key handling complexity while maintaining authentication capability.

Inventive Principle:
Principle #1Segmentation

2Reliability

If home network root key is generated for primary authentication of remote communication device, then authentication security is improved, but impact on existing framework and dependencies on other features increase

Engineering Contradiction:
Improveauthentication securityVSAvoidframework dependency
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The ProSe authentication process extracts the necessary authentication functionality from the primary authentication framework. Instead of generating home network root key and deriving anchor key from it, the system directly uses access authentication key from the authentication vector, taking out only the essential authentication elements needed for ProSe while leaving the primary authentication framework intact and avoiding unnecessary dependencies.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20250031039A1Authentication for a proximity-based service in a wireless communication network
Publication Date: 2025.01.23 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20250031039A1 patent drawing
  • US20250031039A1 patent drawing
  • US20250031039A1 patent drawing

AI summary

A remote communication device performs an authentication procedure with a home communication network, via a relay communication device, to authenticate the remote communication device to the home communication network for a proximity-based service, ProSe. Performing the authentication procedure comprises deriving one or more keys included in an authentication vector. The remote communication device generates an anchor key for the ProSe directly from the one or more keys included in the authentication vector. The remote communication device protects ProSe direct communication between the remote communication device and the relay communication device using security key material derived from the anchor key.