ProSe Application Code Security via Server-Side Signing and Timer Updates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
ProSe services face challenges in securely managing ProSe application codes to prevent illegitimate acquisition or falsification, particularly in ensuring the safety and confidentiality of these codes within the communication provider's management framework.
Innovation Solution
A communication control method involving a terminal device and a server device that manages ProSe application codes through discovery requests, response messages with timers, revocation requests, and code updates to ensure secure and legitimate use of these codes for proximity detection and direct communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If ProSe application code is distributed to terminal devices for proximity detection and direct communication, then the service functionality and user experience are improved, but the risk of illegitimate acquisition or falsification by third parties increases
Solution Approach 1:
The patent applies preliminary action by establishing security infrastructure before code distribution. The ProSe application code is signed by the ProSe server's private key in advance, and terminal devices are pre-configured with the server's public key for verification. This preliminary cryptographic setup prevents third-party impersonation before the code distribution process begins, resolving the security risk while maintaining service functionality.
Solution Approach 2:
The patent uses the ProSe server as an intermediary that mediates between code generation and distribution. The server signs codes with its private key and provides verification mechanisms to terminal devices. This intermediary role ensures that only authenticated codes from legitimate providers are distributed, preventing illegitimate acquisition while enabling widespread code distribution for service functionality.
2Reliability
If ProSe application code is updated or revoked dynamically, then the security and confidentiality management is improved, but the system complexity and management overhead increase
Solution Approach 1:
The patent implements feedback mechanisms where terminal devices periodically verify code validity by checking signatures against the ProSe server's public key. The server can revoke codes by notifying terminal devices of signature changes or distributing revocation lists. This continuous feedback loop maintains code security and confidentiality through dynamic updates without requiring complex centralized control at each device, managing system complexity through standardized verification protocols.
3Productivity
If multiple ProSe application codes are distributed to multiple terminal devices, then the coverage and service availability are improved, but the risk of code misuse or unauthorized access increases
Solution Approach 1:
The patent applies preliminary action by embedding cryptographic signatures in each ProSe application code before distribution to multiple terminal devices. Each code contains a unique signature from the ProSe server that enables verification of its authenticity. This preliminary security measure ensures that even when codes are widely distributed for service availability, each code can be verified to prevent misuse or unauthorized access by unauthorized devices.
Data Source
Figure 1
Figure 2(a)~2(b)
Figure 3
AI summary
There is provided a User Equipment (UE) comprising a transmitting and receiving unit configured to: send, to a device having a ProSe function, a discovery request containing: a ProSe application ID, a command set to announcement, and the UE's IMSI, and receive, from the device having the ProSe function, a discovery response as a response to the discovery request, the discovery response containing: a first ProSe application code corresponding to the ProSe application ID, and a first timer value associated with the first ProSe application code; and a control unit configured to start a timer with the first timer value, based on the reception of the first ProSe Application code associated with the first timer value in the discovery response, wherein the transmitting and receiving unit is further configured to be able to send the first ProSe application code until the timer with the first timer value expires, in a procedure to update the first ProSe Application Code, the transmitting and receiving unit is further configured to receive, from the device having the ProSe function, an update request message containing: the UE's IMSI, a second ProSe application code for the ProSe application ID, and a second timer value for the second ProSe application code, the control unit is further configured to replace the first ProSe application code with the second ProSe application code, in a case of receiving the update request message, and the procedure is the procedure initiated by the device having the ProSe function, and started by sending the update request message.