Sub-talkgroup Formation via Security Token Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication systems for mobile radios lack efficient methods for group calling, particularly for public-safety users who require direct mobile-to-mobile communication and group calling functionalities, especially when out of range from wireless infrastructure.
Innovation Solution
A mobile radio system equipped with both infrastructure wireless communication and short-range wireless communication interfaces, utilizing a talkgroup-specific security token to authenticate and form sub-talkgroups, enabling secure and efficient group communication through a combination of infrastructure and ad-hoc networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If mobile radios use infrastructure wireless communication for group calling, then communication reliability is improved when infrastructure is available, but communication capability is lost when out of range from wireless infrastructure
Solution Approach 1:
The system dynamically switches between infrastructure-based communication and ad-hoc mesh network communication based on availability. Mobile radios automatically transition from infrastructure mode to peer-to-peer mesh networking when out of range, ensuring continuous communication capability across varying operational conditions
Solution Approach 2:
The patent introduces security tokens as intermediaries that enable authenticated communication between mobile radios. These tokens facilitate secure direct communication in ad-hoc mode and secure infrastructure-based communication, acting as a mediator that works across both communication modes
2Adaptability or versatility
If mobile radios establish direct mobile-to-mobile communication, then communication independence is improved when out of range, but security authentication complexity increases
Solution Approach 1:
Security tokens are pre-distributed to authorized mobile radios before direct communication occurs. This preliminary provisioning of authentication credentials eliminates the need for complex real-time authentication protocols during ad-hoc communication, simplifying the interaction while maintaining security
Solution Approach 2:
The system uses security tokens as simplified copies or representations of complex authentication mechanisms. Instead of implementing full authentication protocols between devices, mobile radios use these token copies to verify authorization, reducing computational and procedural complexity
3Reliability
If mobile radios use infrastructure wireless communication for group calling, then security management is improved through centralized control, but communication availability deteriorates when infrastructure is unavailable
Solution Approach 1:
The patent segments security management into two layers: centralized infrastructure-based security when available, and distributed peer-to-peer security using pre-shared tokens when infrastructure is unavailable. This segmentation allows the system to maintain security while adapting to infrastructure availability
Solution Approach 2:
The system changes the security management parameter from centralized infrastructure-dependent to distributed token-based authentication based on infrastructure availability. This parameter change enables the system to maintain secure communication across different operational environments
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A process carried out by a first mobile radio for joining a sub-talkgroup of a first talkgroup includes receiving, via a provisioning process or via an infrastructure wireless communication interface from an infrastructure radio access network (RAN) while within wireless communication range of the RAN, a talkgroup-specific security token associated with and shared by all group mobile radios in a first talkgroup to which the first mobile radio is subscribed via the RAN. The first mobile radio then detects, via a short-range wireless communication interface, a second mobile radio, and authenticates, the second mobile radio using the talkgroup-specific security token. If the authentication is successful, the first mobile radio adds an identity of the second mobile radio to a sub-talkgroup set of mobile radios of the first talkgroup.