UE Discovery Message Protection via LTK-Based Key Derivation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 5G network communications, the protection of discovery messages is compromised when enabled ranging UE possesses an expired discovery key and is outside the 5G network coverage, leading to risks of key leakage and degraded user experience.
Innovation Solution
A method and apparatus for protecting UE discovery messages, where a first UE outside network coverage monitors a first announcement message containing a discovery message encrypted with a discovery key derived from a long-term key (LTK) received when the UE was within the network coverage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If discovery messages are encrypted using discovery keys for UE outside network coverage, then message privacy is protected, but key security is compromised due to expired discovery keys
Solution Approach 1:
The network receives and stores the UE's identity information before the UE goes out of coverage. This preliminary action enables the network to proactively generate and send updated security keys (Ks and NAS key) to the UE while it is still in coverage, ensuring key validity before the UE transitions to out-of-coverage mode where it cannot access the network for key updates.
Solution Approach 2:
The network acts as an intermediary that bridges the security gap for out-of-coverage UE. By storing UE identity information and serving as a trusted third party to generate and distribute updated security keys, the network enables secure discovery message encryption even when the UE cannot directly communicate with the network for key management.
2Reliability
If discovery keys are provided with expiration periods for UE within network coverage, then key security is improved, but UE experience is degraded when UE moves outside coverage with expired keys
Solution Approach 1:
The system performs preliminary key update actions by storing UE identity information and proactively sending updated security keys to the UE while it is still in network coverage. This ensures that the UE has valid keys before leaving coverage, preventing service interruption and maintaining good UE experience.
Solution Approach 2:
The network prepares security key updates in advance before the UE's discovery key expires. By storing UE identity information and initiating key update procedures while the UE is still in coverage, the system cushions against the potential service disruption that would occur if the UE attempted to use expired keys after leaving coverage.
3Reliability
If UE stores LTK for determining discovery keys outside network coverage, then discovery message protection is enabled, but device complexity increases
Solution Approach 1:
The patent extracts the complex key management operations from the UE and relocates them to the network side. The network stores UE identity information, generates security keys, and manages key distribution, while the UE only needs to store the LTK and follow simple key derivation procedures. This extraction significantly reduces device complexity while maintaining discovery message protection.
Solution Approach 2:
The network serves as an intermediary that handles the complex key management tasks. Instead of requiring the UE to manage multiple discovery keys and their expiration states, the network intermediates by storing identity information, generating appropriate security keys, and distributing them to the UE, thereby simplifying the UE's key management burden.
Data Source
AI summary
A UE discovery message protection method, includes: when a first UE is located outside network coverage, monitoring a first announcement message, where the first announcement message includes: a discovery message, which is encrypted on the basis of a discovery key, and an LTK ID, which indicates a LTK; and determining the discovery key on the basis of the LTK corresponding to the LTK ID, where the LTK is received when the first UE is within the network coverage.


