5G NR Sidelink Key Derivation for Secure UE Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for improved security in sidelink communication within 5G NR technology to ensure secure communication between user equipment (UEs) and base stations, particularly in establishing and maintaining secure sidelink connections.

Innovation Solution

The method involves transmitting and receiving security mode command messages between a UE and a base station to identify and verify encryption keys for secure sidelink communication, including RRC and user plane encryption keys, and physical layer sidelink encryption keys, to authenticate and establish secure communication with other UEs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional sidelink communication is used without enhanced security protocols, then device complexity and setup procedures are reduced, but security and integrity of communication between UEs and base stations deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary security setup by establishing secure sidelink connections before actual data transmission occurs. The base station configures encryption keys and security parameters in advance through RRC reconfiguration messages, ensuring that when sidelink communication begins, security infrastructure is already in place. This preliminary configuration enables secure communication without requiring complex real-time security negotiations during data transfer.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The base station serves as an intermediary that facilitates secure sidelink communication between UEs. Instead of UEs directly establishing secure connections with each other, the base station mediates by distributing encryption keys (KSL, KRRCenc, KUPenc) and security parameters to multiple UEs. This intermediary approach simplifies the security architecture by centralizing security management at the base station while maintaining secure peer-to-peer communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple encryption keys and security protocols are implemented, then security and integrity of sidelink communications are improved, but the number of message types and signaling procedures increases

Engineering Contradiction:
ImproveintegrityVSAvoidnumber of message types
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes security-related message types universal by having the base station use the same RRC reconfiguration message for multiple purposes: distributing encryption keys, configuring security parameters, and establishing secure sidelink connections. This multi-functional approach eliminates the need for separate dedicated security setup messages, reducing the total number of message types while maintaining comprehensive security coverage through multiple encryption layers (physical layer, RRC layer, user plane).

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12425846B2Secure sidelink communication
Publication Date: 2025.09.23 QUALCOMM INC
  • US12425846B2 patent drawing
  • US12425846B2 patent drawing
  • US12425846B2 patent drawing

AI summary

Aspects present herein relate to methods and devices for wireless communication including an apparatus, e.g., a UE and/or a base station. The apparatus may receive, from a base station, a security mode command message associated with secure sidelink communication with at least one other UE. The apparatus may also identify, based on the security mode command message, at least one of a RRC encryption key or a user plane encryption key. Additionally, the apparatus may receive, from the base station, an indication of at least one of a common base key or the RRC encryption key. The apparatus may also identify a physical layer sidelink encryption key based on at least one of the common base key or the RRC encryption key, the physical layer sidelink encryption key being associated with the secure sidelink communication with the at least one other UE.