Secure Proximity Services Authentication for Direct Device Communication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Proximity services in communication systems introduce security challenges, such as direct device-to-device communication without network authentication and the inability to perform Lawful Interception, as user traffic bypasses traditional network infrastructure, leading to concerns about unauthorized use and lack of traffic monitoring.
Innovation Solution
The Secure Proximity Services (SeProSe) methodology establishes security associations between devices by authenticating and authorizing users through the network, using a common secret key for secure communication and enabling network oversight of direct traffic, allowing for Lawful Interception by modifying transmission parameters to ensure network access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If direct device-to-device communication is enabled for proximity services, then communication efficiency and user experience are improved, but security control and network authentication are compromised
Solution Approach 1:
The network acts as an intermediary that establishes security associations between devices before allowing direct communication. The network core infrastructure mediates the authentication process and provides security keys to authorized devices, enabling them to communicate directly while maintaining network-controlled security oversight.
Solution Approach 2:
Security associations and authentication are performed in advance before direct device-to-device communication begins. The network authenticates devices and establishes security contexts beforehand, so that when direct communication occurs, security control is already in place without requiring real-time network involvement in each communication act.
2Speed
If user traffic bypasses network infrastructure for proximity services, then communication speed and efficiency are improved, but Lawful Interception capability is lost
Solution Approach 1:
The network maintains an intermediary role by providing security context information to authorized entities. While user traffic flows directly between devices for speed, the network retains the ability to provide Lawful Interception support by sharing relevant security context and metadata with authorized monitoring entities.
Solution Approach 2:
Different parts of the communication system have different functions: direct device-to-device links handle high-speed user traffic, while the network core infrastructure handles security management and Lawful Interception support. Each component performs its specialized function optimally.
3Ease of operation
If network authentication is removed for proximity services, then device autonomy and ease of operation are improved, but unauthorized access and security risks increase
Solution Approach 1:
Devices perform self-authentication using security context information provided by the network in advance. The devices autonomously verify each other's credentials and establish secure communication without real-time network involvement, providing both device autonomy and security assurance.
Solution Approach 2:
The network performs authentication and authorization in advance, providing security context to authorized devices before direct communication begins. This preliminary security setup enables devices to autonomously communicate securely without requiring continuous network authentication.
Data Source
Figure 1A~1B
Figure 2A
Figure 2B
AI summary
Techniques are disclosed for establishing secure communications between computing devices utilizing proximity services in a communication system. For example, a method for providing secure communications in a communications system comprises the following steps. At least one key is sent from at least one network element of an access network to a first computing device and at least a second computing device. The first computing device and the second computing device utilize the access network to access the communication system and are authenticated by the access network prior to the key being sent. The key is useable by the first computing device and the second computing device to securely communicate with one another when in proximity of one another without communications between the first computing device and the second computing device going through the access network.