ProSe Group Communication Security Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Proximity Based Service (ProSe) communication systems lack robust security measures, making them vulnerable to malicious information transmission during disaster situations, and face inefficiencies in device-to-device (D2D) group communication, particularly in public safety scenarios.

Innovation Solution

A method and system for D2D group communication that includes obtaining necessary information and security keys to enable secure ProSe discovery and communication, involving a Mobility Management Entity (MME), ProSe function server, and user equipment (UE) to authenticate and verify group membership, generate, and exchange security keys for secure ProSe group communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional Proximity Based Service (ProSe) communication systems are used for D2D group communication, then communication can be established between devices, but security measures are insufficient making the system vulnerable to malicious information transmission

Engineering Contradiction:
ImprovesecurityVSAvoidmalicious information transmission
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by performing authentication and security key establishment before D2D group communication begins. The network authenticates UEs and establishes security context in advance, ensuring that only authorized devices can communicate. This prevents malicious information transmission by verifying device legitimacy before communication occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses the network (MME, ProSe function server) as an intermediary to manage security for D2D group communication. The network distributes security keys, authenticates devices, and verifies group membership, acting as a trusted mediator that prevents malicious transmissions without requiring complex peer-to-peer security mechanisms between devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security measures are enhanced for D2D group communication, then security reliability improves, but system complexity increases due to additional authentication and key management procedures

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication and key management procedures
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent reduces device complexity by offloading security management to the network intermediary. The MME and ProSe function server handle authentication, security context establishment, and key distribution, while UEs simply follow standardized procedures. This maintains high security reliability without burdening devices with complex security implementations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent uses existing network infrastructure (MME, ProSe function server) for multiple purposes including authentication, security key management, and group membership verification. This universal approach allows the same network elements to handle various security requirements without adding dedicated complex security hardware or software to each device.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If D2D group communication is performed without proper security configuration, then ease of operation is improved, but security vulnerability increases

Engineering Contradiction:
ImproveD2D group communication setupVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent enables UEs to automatically perform security procedures without user intervention. The devices autonomously authenticate with the network, receive security keys, and configure security parameters based on network instructions. This self-service approach maintains ease of operation while ensuring security is properly established through automated network-controlled procedures.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10382955B2Security method and system for supporting prose group communication or public safety in mobile communication
Publication Date: 2019.08.13 SAMSUNG ELECTRONICS CO LTD
  • US10382955B2 patent drawing
  • US10382955B2 patent drawing
  • US10382955B2 patent drawing

AI summary

A method for communicating by a terminal, includes transmitting, to an MME, an attach request message including a public safety indication and/or a group communication indication; receiving, from the MME, an attach accept message including at least one type of information from among a ProSe identifier, a ProSe group identifier, and a ProSe group for performing a ProSe, ProSe-related functions of the terminal, and a proximity-related security key (ProSe key) The method further includes transmitting a ProSe registration request to a ProSe function server and receiving, from the ProSe function server, a ProSe registration response message pending authentication of the terminal.