TLS Signature Verification for Secure Group Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multicast communication protocols, such as TLS and DTLS, lack effective mechanisms for authenticating the source of messages in group communication scenarios, requiring nodes to share the same key material and preventing verification of message sources.

Innovation Solution

Augmenting the Transport Layer Security (TLS) protocol with signature verification information, including digital signatures and public signature keys, to enable secure group communication by allowing receivers to verify the authenticity of messages using separate key materials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If symmetric group keys are used for multicast communication, then communication efficiency is improved, but source authentication capability deteriorates

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidsource authentication capability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the key material into two distinct parts: symmetric group keys for efficient encryption/decryption of multicast messages, and asymmetric signature verification keys for authenticating the message source. This segmentation allows each key type to perform its specialized function without interfering with the other, resolving the contradiction between communication efficiency and authentication capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces asymmetric cryptography (public-key infrastructure) to provide source authentication in multicast communication. Each node possesses a unique key pair (private key for signing, public key for verification), creating an asymmetric relationship that enables individual source identification while maintaining symmetric key efficiency for bulk message encryption. This asymmetry resolves the authentication limitation of symmetric-only approaches.

Inventive Principle:
Principle #4Asymmetry

2Reliability

If separate key materials are used for each node, then source verification is improved, but key distribution complexity increases

Engineering Contradiction:
Improvesource verification capabilityVSAvoidkey distribution complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the asymmetric signature verification mechanism universally applicable to all nodes in the multicast group. Each node independently possesses its own key pair and can verify signatures from any other node using the same verification process. This universal verification capability simplifies key distribution compared to pairwise approaches, as nodes don't need to exchange or store multiple individual keys for different counterparts.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent establishes asymmetric key pairs in advance during node initialization, before multicast communication begins. Each node pre-generates its own private-public key pair and stores it locally. This preliminary key generation eliminates the need for complex runtime key distribution protocols, as each node already has the verification capability ready when multicast messages arrive.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12452083B2Security for group communication
Publication Date: 2025.10.21 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US12452083B2 patent drawing
  • US12452083B2 patent drawing
  • US12452083B2 patent drawing

AI summary

A method for enabling secure group communication in a communication network is performed in a sending node and includes providing signature verification related information to a plurality of listening nodes and sending a group message to the plurality of listening nodes, the group message including signature verification related information of the sending node. A method, nodes, computer programs, and a computer program product enabling secure group communication in a communication network are also presented.