Relay UE Security Association Segmentation for Sidelink Mesh
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless mesh networks face challenges in establishing secure connections between remote user equipment (UEs) traversing one or more intermediary relay UEs, without relying on a priori shared secrets or network involvement.
Innovation Solution
The method involves a relay UE receiving a communication request message from a first neighbor UE, modifying it to include security-establishment-related information for establishing a security association between the relay UE and a second neighbor UE, and transmitting the modified message to establish secure connections between the initiating UE, the relay UE, and the target UE.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a relay UE forwards communication request messages between remote UEs, then connectivity between remote UEs is enabled, but security against monitoring or tampering by intermediary relay UEs deteriorates
Solution Approach 1:
The security association is segmented into multiple hop-specific associations. Each relay UE establishes a separate security association with its neighboring UEs (first neighbor UE and second neighbor UE), rather than relying on a single end-to-end security association. This segmentation allows each hop to be secured independently, preventing any single relay UE from monitoring or tampering with the entire communication path.
Solution Approach 2:
The patent introduces intermediary security associations at each hop. Each relay UE acts as an intermediary that establishes its own security context with the UEs it connects, rather than simply forwarding unsecured messages. This intermediary security mechanism ensures that relay UEs cannot access or tamper with the communication content while still enabling connectivity between remote UEs.
2Object-affected harmful factors
If security associations are established at each hop, then security against intermediary monitoring is improved, but device complexity increases
Solution Approach 1:
The patent merges the security association establishment process with the existing communication request message forwarding mechanism. The relay UE modifies the communication request message by adding security-establishment-related information for the next hop while forwarding the message. This merging approach integrates security association setup into the normal message forwarding flow, avoiding separate complex security protocols at each hop.
Solution Approach 2:
The communication request message serves multiple functions: it carries user data, establishes security associations at each hop, and enables relay UE to forward messages. By making the message structure universal and multi-functional, the patent avoids the need for separate security protocols, thereby reducing overall system complexity while achieving per-hop security.
3Object-affected harmful factors
If relay UEs modify communication request messages to add security information, then end-to-end security is improved, but message processing complexity increases
Solution Approach 1:
Each relay UE adds security-establishment-related information specific to its own context (first neighbor UE and second neighbor UE) while preserving the original message content from the initiating UE. This local quality approach ensures that each hop's security information is added only where needed, without requiring the relay UE to process or validate the entire end-to-end security path, thereby limiting message processing complexity to local operations.
Data Source
AI summary
A method of a relay user equipment (UE) can include receiving, at the relay UE, from a first neighbor UE, a communication request message for establishing a connection between an initiating UE and a target UE, the communication request message including first security-establishment-related information originating from the initiating UE for establishing a security association between the initiating UE and the target UE; modifying the communication request message to add second security-establishment-related information for establishing a security association between the relay UE and a second neighbor UE; and transmitting to the second neighbor UE the modified communication request message that includes the first security-establishment-related information originating from the initiating UE for establishing the security association between the initiating UE and the target UE, and the second security-establishment-related information added by the relay UE for establishing the security association between the relay UE and the second neighbor UE.


