ProSe Group Communication Security Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional Proximity Based Service (ProSe) communication systems lack robust security measures, making them vulnerable to malicious information transmission during disaster situations, and face inefficiencies in device-to-device (D2D) group communication, particularly in public safety scenarios.
Innovation Solution
A method and system for D2D group communication that includes obtaining necessary information and security keys to enable secure ProSe discovery and communication, involving a Mobility Management Entity (MME), ProSe function server, and user equipment (UE) to authenticate and verify group membership, generate, and exchange security keys for secure ProSe group communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional Proximity Based Service (ProSe) communication systems are used for D2D group communication, then communication can be established between devices, but security measures are insufficient making the system vulnerable to malicious information transmission
Solution Approach 1:
The patent applies preliminary action by performing authentication and security key establishment before D2D group communication begins. The network authenticates UEs and establishes security context in advance, ensuring that only authorized devices can communicate. This prevents malicious information transmission by verifying device legitimacy before communication occurs.
Solution Approach 2:
The patent uses the network (MME, ProSe function server) as an intermediary to manage security for D2D group communication. The network distributes security keys, authenticates devices, and verifies group membership, acting as a trusted mediator that prevents malicious transmissions without requiring complex peer-to-peer security mechanisms between devices.
2Reliability
If security measures are enhanced for D2D group communication, then security reliability improves, but system complexity increases due to additional authentication and key management procedures
Solution Approach 1:
The patent reduces device complexity by offloading security management to the network intermediary. The MME and ProSe function server handle authentication, security context establishment, and key distribution, while UEs simply follow standardized procedures. This maintains high security reliability without burdening devices with complex security implementations.
Solution Approach 2:
The patent uses existing network infrastructure (MME, ProSe function server) for multiple purposes including authentication, security key management, and group membership verification. This universal approach allows the same network elements to handle various security requirements without adding dedicated complex security hardware or software to each device.
3Ease of operation
If D2D group communication is performed without proper security configuration, then ease of operation is improved, but security vulnerability increases
Solution Approach 1:
The patent enables UEs to automatically perform security procedures without user intervention. The devices autonomously authenticate with the network, receive security keys, and configure security parameters based on network instructions. This self-service approach maintains ease of operation while ensuring security is properly established through automated network-controlled procedures.
Data Source
AI summary
A method for communicating by a terminal, includes transmitting, to an MME, an attach request message including a public safety indication and/or a group communication indication; receiving, from the MME, an attach accept message including at least one type of information from among a ProSe identifier, a ProSe group identifier, and a ProSe group for performing a ProSe, ProSe-related functions of the terminal, and a proximity-related security key (ProSe key) The method further includes transmitting a ProSe registration request to a ProSe function server and receiving, from the ProSe function server, a ProSe registration response message pending authentication of the terminal.


