ProSe Group Key Derivation for Secure Direct Device Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

3GPP SA3 lacks a security solution for authentication and authorization in Proximity-based Service (ProSe) communication, which poses security and privacy risks in direct communication scenarios.

Innovation Solution

A method and system for performing authentication and authorization in ProSe communication by deriving session keys Kpc and Kpi from a unique key Kp at requesting and receiving devices, using these keys for confidentiality and integrity protection in ProSe communication setups, ensuring secure direct communication between devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If direct communication is enabled between proximal devices without network infrastructure, then service availability and accessibility are improved, but security vulnerabilities and unauthorized access risks increase

Engineering Contradiction:
Improveservice availabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by establishing security credentials and group keys before direct communication occurs. The network provides authentication credentials to devices in advance, and group keys are pre-established for potential communication groups. This allows devices to securely communicate directly without network infrastructure while maintaining security through pre-configured authentication mechanisms.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses an intermediary approach by introducing a trusted group key mechanism that mediates between devices and the network. The group key acts as a shared secret among authorized devices, enabling them to authenticate each other directly without continuous network involvement. This intermediary key structure allows secure peer-to-peer communication while maintaining network-controlled security policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security protocols are implemented for direct communication, then authentication and authorization are improved, but system complexity and overhead increase

Engineering Contradiction:
ImproveauthenticationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing a group key mechanism that serves multiple security functions simultaneously. The same group key structure provides both authentication (verifying device identity) and authorization (controlling access rights) for direct communication. This multi-functional approach reduces overall system complexity compared to implementing separate authentication and authorization protocols.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses parameter changes by transitioning from individual device-specific security protocols to a group-based key parameter structure. Instead of managing complex individual credentials for each device pair, the system changes to a group key parameter that simplifies the security model. This parameter transformation reduces computational overhead and simplifies the authentication and authorization process while maintaining strong security.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240314112A1Authentication and authorization in proximity based service communication using a group key
Publication Date: 2024.09.19 NEC CORP
  • US20240314112A1 patent drawing
  • US20240314112A1 patent drawing
  • US20240314112A1 patent drawing

AI summary

A method of performing authentication and authorization in Proximity based Service (ProSe) communication by a requesting device which sends a request of a communication and a receiving device which receives the request from the requesting device, the method including deriving session keys Kpc and Kpi from an unique key Kp at the requesting and receiving devices, using the session keys Kpc and Kpi for ProSe communication setup and direct communication between the requesting and receiving devices, starting the direct communication with the requesting and receiving devices. The key Kpc is confidentiality key and the key Kpi is integrity protection key.