ProSe Group Key Derivation for Secure Direct Device Communication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
3GPP SA3 lacks a security solution for authentication and authorization in Proximity-based Service (ProSe) communication, which poses security and privacy risks in direct communication scenarios.
Innovation Solution
A method and system for performing authentication and authorization in ProSe communication by deriving session keys Kpc and Kpi from a unique key Kp at requesting and receiving devices, using these keys for confidentiality and integrity protection in ProSe communication setups, ensuring secure direct communication between devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If direct communication is enabled between proximal devices without network infrastructure, then service availability and accessibility are improved, but security vulnerabilities and unauthorized access risks increase
Solution Approach 1:
The patent applies preliminary action by establishing security credentials and group keys before direct communication occurs. The network provides authentication credentials to devices in advance, and group keys are pre-established for potential communication groups. This allows devices to securely communicate directly without network infrastructure while maintaining security through pre-configured authentication mechanisms.
Solution Approach 2:
The patent uses an intermediary approach by introducing a trusted group key mechanism that mediates between devices and the network. The group key acts as a shared secret among authorized devices, enabling them to authenticate each other directly without continuous network involvement. This intermediary key structure allows secure peer-to-peer communication while maintaining network-controlled security policies.
2Reliability
If security protocols are implemented for direct communication, then authentication and authorization are improved, but system complexity and overhead increase
Solution Approach 1:
The patent applies universality by designing a group key mechanism that serves multiple security functions simultaneously. The same group key structure provides both authentication (verifying device identity) and authorization (controlling access rights) for direct communication. This multi-functional approach reduces overall system complexity compared to implementing separate authentication and authorization protocols.
Solution Approach 2:
The patent uses parameter changes by transitioning from individual device-specific security protocols to a group-based key parameter structure. Instead of managing complex individual credentials for each device pair, the system changes to a group key parameter that simplifies the security model. This parameter transformation reduces computational overhead and simplifies the authentication and authorization process while maintaining strong security.
Data Source
AI summary
A method of performing authentication and authorization in Proximity based Service (ProSe) communication by a requesting device which sends a request of a communication and a receiving device which receives the request from the requesting device, the method including deriving session keys Kpc and Kpi from an unique key Kp at the requesting and receiving devices, using the session keys Kpc and Kpi for ProSe communication setup and direct communication between the requesting and receiving devices, starting the direct communication with the requesting and receiving devices. The key Kpc is confidentiality key and the key Kpi is integrity protection key.


