ProSe Application Code Security via Server-Side Signing and Timer Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

ProSe services face challenges in securely managing ProSe application codes to prevent illegitimate acquisition or falsification, particularly in ensuring the safety and confidentiality of these codes within the communication provider's management framework.

Innovation Solution

A communication control method involving a terminal device and a server device that manages ProSe application codes through discovery requests, response messages with timers, revocation requests, and code updates to ensure secure and legitimate use of these codes for proximity detection and direct communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If ProSe application code is distributed to terminal devices for proximity detection and direct communication, then the service functionality and user experience are improved, but the risk of illegitimate acquisition or falsification by third parties increases

Engineering Contradiction:
ImproveProSe service functionalityVSAvoidSecurity risk of code acquisition
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by establishing security infrastructure before code distribution. The ProSe application code is signed by the ProSe server's private key in advance, and terminal devices are pre-configured with the server's public key for verification. This preliminary cryptographic setup prevents third-party impersonation before the code distribution process begins, resolving the security risk while maintaining service functionality.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses the ProSe server as an intermediary that mediates between code generation and distribution. The server signs codes with its private key and provides verification mechanisms to terminal devices. This intermediary role ensures that only authenticated codes from legitimate providers are distributed, preventing illegitimate acquisition while enabling widespread code distribution for service functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If ProSe application code is updated or revoked dynamically, then the security and confidentiality management is improved, but the system complexity and management overhead increase

Engineering Contradiction:
ImproveCode security managementVSAvoidCode management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements feedback mechanisms where terminal devices periodically verify code validity by checking signatures against the ProSe server's public key. The server can revoke codes by notifying terminal devices of signature changes or distributing revocation lists. This continuous feedback loop maintains code security and confidentiality through dynamic updates without requiring complex centralized control at each device, managing system complexity through standardized verification protocols.

Inventive Principle:
Principle #23Feedback

3Productivity

If multiple ProSe application codes are distributed to multiple terminal devices, then the coverage and service availability are improved, but the risk of code misuse or unauthorized access increases

Engineering Contradiction:
ImproveService availabilityVSAvoidCode misuse risk
Core Design Contradiction:
ProductivityVSObject-generated harmful factors

Solution Approach 1:

The patent applies preliminary action by embedding cryptographic signatures in each ProSe application code before distribution to multiple terminal devices. Each code contains a unique signature from the ProSe server that enables verification of its authenticity. This preliminary security measure ensures that even when codes are widely distributed for service availability, each code can be verified to prevent misuse or unauthorized access by unauthorized devices.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3509386B1User equipment, prose server and coresponding methods for updating a prose application code
Publication Date: 2021.07.21 SHARP KK
  • EP3509386B1 patent drawingFigure 1
  • EP3509386B1 patent drawingFigure 2(a)~2(b)
  • EP3509386B1 patent drawingFigure 3

AI summary

There is provided a User Equipment (UE) comprising a transmitting and receiving unit configured to: send, to a device having a ProSe function, a discovery request containing: a ProSe application ID, a command set to announcement, and the UE's IMSI, and receive, from the device having the ProSe function, a discovery response as a response to the discovery request, the discovery response containing: a first ProSe application code corresponding to the ProSe application ID, and a first timer value associated with the first ProSe application code; and a control unit configured to start a timer with the first timer value, based on the reception of the first ProSe Application code associated with the first timer value in the discovery response, wherein the transmitting and receiving unit is further configured to be able to send the first ProSe application code until the timer with the first timer value expires, in a procedure to update the first ProSe Application Code, the transmitting and receiving unit is further configured to receive, from the device having the ProSe function, an update request message containing: the UE's IMSI, a second ProSe application code for the ProSe application ID, and a second timer value for the second ProSe application code, the control unit is further configured to replace the first ProSe application code with the second ProSe application code, in a case of receiving the update request message, and the procedure is the procedure initiated by the device having the ProSe function, and started by sending the update request message.