ProSe Relay Key Reuse via Anchor Node Binding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication networks face inefficiencies in reusing ProSe relay user keys across different sessions, which complicates the management of identifiers and burdens authentication servers, deviating from conventional design principles.

Innovation Solution

The introduction of a Proximity Services Anchor Node that stores and manages ProSe relay user keys, allowing for their reuse by binding identifiers, and the use of ProSe reuse signaling to request key reuse without specifying identities, thereby insulating other network nodes and allowing authentication servers to manage only subscription IDs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a new ProSe relay user key is generated each time the remote wireless communication device establishes an interface with a relay wireless communication device, then security of the interface is improved, but authentication efficiency deteriorates due to requiring re-running primary authentication

Engineering Contradiction:
Improveinterface securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs primary authentication and generates the ProSe relay user key in advance during initial network attachment. The authentication server stores the subscription ID and the generated key, enabling subsequent relay interfaces to reuse the pre-generated key without re-running authentication, thus resolving the contradiction between security and authentication efficiency

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a copy of the authentication credentials (subscription ID and ProSe relay user key) and stores them in the authentication server's database. This copied credential set can be rapidly retrieved and reused for subsequent relay interfaces, eliminating the need to re-run primary authentication while maintaining security through the use of the original key material

Inventive Principle:
Principle #26Copying

2Productivity

If the ProSe relay user key is reused across different sessions, then authentication efficiency is improved, but device complexity increases due to managing identifiers bound to keys

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidkey management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent extracts the key management function from individual network nodes and centralizes it in the authentication server. The authentication server alone manages the binding between subscription IDs and ProSe relay user keys, while other nodes simply use the subscription ID for identification. This extraction eliminates the complexity of managing key identifiers across multiple nodes while enabling efficient key reuse

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent makes the subscription ID a universal identifier that serves multiple functions: it identifies the remote wireless communication device in conventional authentication scenarios and also serves as the key to retrieve the bound ProSe relay user key for relay interface authentication. This multi-functionality eliminates the need for separate key identifier management while enabling efficient key reuse across different sessions

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If the authentication server manages identifiers bound to ProSe relay user keys, then key reuse is enabled, but the burden on the authentication server increases deviating from conventional design principles

Engineering Contradiction:
Improvekey reuse capabilityVSAvoidauthentication server burden
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges the key identifier management function into the existing subscription ID management framework. Instead of creating a separate identifier system for keys, the authentication server uses the already-managed subscription ID as the binding key. This merging enables key reuse capability while avoiding additional management burdens, as the authentication server continues to manage only subscription IDs as in conventional design

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20250106018A1Security for traffic relaying by a wireless communication device
Publication Date: 2025.03.27 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20250106018A1 patent drawing
  • US20250106018A1 patent drawing
  • US20250106018A1 patent drawing

AI summary

A method performed by an authentication server is provided. The method comprises receiving a request for authentication of a remote wireless communication device, wherein the request requests reuse of a proximity services relay user key for deriving a shared key for protecting an interface between the remote wireless communication device and a relay wireless communication device, wherein the relay wireless communication device is configured to relay traffic for the remote wireless communication device.