Proximity Communication Key Updates for Secure Relay Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G communication systems, there is a security risk in proximity-based services due to the long-term use of remote user keys, leading to potential key leakage and malicious monitoring, which compromises network communication security.

Innovation Solution

Implement an update mechanism for remote user keys by determining whether they need updating and performing authorization checks to ensure secure network communication, including generating new keys when necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If remote user keys are used long-term for authentication, then authentication efficiency is improved, but security risk increases due to key leakage and malicious monitoring

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidnetwork communication security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements periodic key updates by introducing a key update timer that expires after a predetermined time period. When the timer expires, the system automatically triggers a key update procedure where the remote terminal device generates a new remote user key and notifies the network side, thereby periodically refreshing authentication credentials to prevent long-term key exposure while maintaining efficient authentication operations.

Inventive Principle:
Principle #19Periodic action

2Reliability

If key update mechanism is implemented, then network communication security is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork communication securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service key update where the remote terminal device autonomously manages its own authentication key lifecycle. The device automatically generates new keys, notifies the network side, and handles key expiration without requiring manual intervention or complex network coordination, thereby simplifying the overall system architecture while maintaining security.

Inventive Principle:
Principle #25Self-service

3Reliability

If authorization check is performed on relay service, then network security is improved, but communication time increases

Engineering Contradiction:
Improvenetwork securityVSAvoidcommunication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs authorization checks in advance during the key update notification process before actual communication begins. The network side validates whether the remote terminal device is authorized to use relay service when receiving the key update notification, and only allows key updates for authorized devices. This preliminary authorization verification ensures security while minimizing time impact by completing checks before data transmission starts.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250260979A1Communication method and communication apparatus
Publication Date: 2025.08.14 HUAWEI TECH CO LTD
  • US20250260979A1 patent drawing
  • US20250260979A1 patent drawing
  • US20250260979A1 patent drawing

AI summary

Embodiments of this application provide a communication method and a communication apparatus. The method includes: A first communication apparatus determines whether a first remote user key needs to be updated, and when determining that the first remote user key does not need to be updated, initiates a proximity-based service authentication request. An authentication server function network element obtains the first remote user key and a subscription permanent identifier of the first communication apparatus, and when determining that the first communication apparatus has permission to use a relay service, generates a first proximity-based service key, where the first proximity-based service key is used by the first communication apparatus to establish a security connection to a second communication apparatus, to provide a proximity-based service. This improves user experience when ensuring secure network communication on a proximity-based service control plane.