Secured User Equipment Relay via Asymmetric Cryptography

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing ProSe-enabled user equipment (UE) integration into 3GPP New Radio (NR) networks faces challenges in establishing secure, end-to-end unicast links, particularly when UEs are in proximity and lack direct communication capabilities, necessitating the use of relay UEs without compromising security.

Innovation Solution

The implementation of asymmetric and symmetric cryptography protocols, such as RSA, ECC, and Diffie-Hellman key agreement, allows UEs to negotiate and establish secure connections via relay UEs, ensuring that the relay does not have visibility into the security context, using public-key cryptography and Layer-2 IDs to maintain message opacity while enabling secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If relay UEs are used to enable communication between proximate UEs, then communication capability is improved, but security is worsened due to relay visibility into messages

Engineering Contradiction:
Improvecommunication capabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an intermediary encryption layer where the relay UE acts as a message forwarder rather than a decoder. The source UE encrypts messages with the target UE's public key, making the relay UE unable to read message contents. This intermediary encryption mechanism allows the relay to perform routing functions while maintaining end-to-end security, resolving the contradiction between enabling relay communication and preserving security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary security setup by establishing public-key pairs and security contexts before relay communication begins. The source and target UEs pre-share security credentials and establish encryption keys in advance, so that when messages pass through the relay, the security framework is already in place. This preliminary action ensures that security is built into the communication flow from the start, preventing security degradation despite relay involvement.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If end-to-end encryption is implemented through relay UEs, then security is improved, but device complexity increases due to cryptography protocols

Engineering Contradiction:
ImprovesecurityVSAvoidcryptography protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the cryptographic complexity from the relay UE and concentrates it only in the source and target UEs. The relay UE is removed from the security processing chain entirely, handling only unencrypted message forwarding and routing. This extraction of cryptographic functions from the relay simplifies the relay device while maintaining end-to-end security through asymmetric cryptography implemented only at the communication endpoints.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses public-key cryptography where public keys are freely shared and copied between UEs without compromising security. The source UE copies the target UE's public key for encryption, and the target UE copies the source UE's public key for decryption. This copying mechanism allows secure communication establishment without complex key exchange protocols involving the relay, reducing overall system complexity while maintaining strong security.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11924184B2Protection of communications through user equipment relay
Publication Date: 2024.03.05 APPLE INC
  • US11924184B2 patent drawing
  • US11924184B2 patent drawing
  • US11924184B2 patent drawing

AI summary

The present application relates to devices and components including apparatus, systems, and methods for secured user equipment communications over a user equipment relay. In some embodiments, symmetric or asymmetric encryption may be used for the secured user equipment communications.