Proxy Key Distribution for UEs Without Key Derivation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Certain user equipment (UE) lack the capability to derive security keys directly, leading to inadequate protection of data transmission with network side devices, compromising security and reliability.

Innovation Solution

A method and apparatus for obtaining a key, where a first UE sends key information to a network side device to enable encryption and/or integrity protection for a second UE, utilizing various key derivation and proxy mechanisms to ensure secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security keys are derived by UE independently, then security protection is improved, but not all UEs can achieve this due to lack of SIM card or calculation capability

Engineering Contradiction:
Improvesecurity protectionVSAvoidUE capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a first UE as an intermediary that has already derived the security key and can assist a second UE (which lacks SIM card or calculation capability) in obtaining the key. The first UE acts as a mediator to bridge the capability gap, allowing the second UE to access security services without having independent key derivation capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal security key sharing mechanism where a first UE can provide security keys to multiple second UEs. This multi-functional approach allows any UE with key derivation capability to serve as a key distributor to other UEs without such capability, making the security system universally accessible despite heterogeneous UE capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If key information is transmitted over air interface, then key distribution is simplified, but security is compromised due to potential eavesdropping

Engineering Contradiction:
Improvekey distributionVSAvoideavesdropping
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The first UE serves as a trusted intermediary that receives key information through secure channels and assists second UEs in obtaining keys without direct transmission over the air interface. This mediator approach eliminates the need for vulnerable direct key transmission while maintaining ease of key distribution to UEs without calculation capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If UEs without SIM card or calculation capability exist, then device versatility is improved, but data transmission security reliability deteriorates

Engineering Contradiction:
Improvedevice versatilityVSAvoiddata transmission security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent enables UEs without SIM card or calculation capability to maintain data transmission security by introducing a first UE as a mediator. The first UE derives the security key and provides it to the second UE through secure means, allowing the second UE to participate in secure communications despite lacking independent key derivation capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system allows UEs without calculation capability to still access security services by having the first UE perform the key derivation and sharing process. The second UE benefits from security protection without needing to independently perform key derivation operations, effectively allowing less capable devices to serve themselves through the intermediary's capabilities.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12425849B2Method and apparatus for obtaining key, user equipment, and network side device
Publication Date: 2025.09.23 VIVO MOBILE COMM CO LTD
  • US12425849B2 patent drawing
  • US12425849B2 patent drawing
  • US12425849B2 patent drawing

AI summary

A method for obtaining a key includes sending, by a first UE, first key information to a network side device, where the first key information is used for indicating a first key of a second UE, and the first key is used for performing encryption and/or integrity protection on data in communication between the second UE and the network side device.