Zero-Knowledge Key Verification for UE-to-UE Sidelink Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Supervisory devices in 3GPP communication systems lack the capability to monitor UE to UE relay scenarios, as existing key negotiation protocols like DH (Diffie-Hellman) are vulnerable to attacks and do not facilitate key acquisition by the supervisory device.

Innovation Solution

Implement a key verification method using zero-knowledge proof to ensure that a supervisory device can decrypt ciphertext information and obtain the communication key determined by terminals, enabling monitoring in UE to UE relay scenarios.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional key negotiation protocols (e.g., Diffie-Hellman) are used in UE to UE relay scenarios, then key exchange between terminals can be achieved, but the supervisory device cannot acquire the communication key for monitoring

Engineering Contradiction:
Improvemonitoring capabilityVSAvoidkey acquisition
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces a supervisory device as an intermediary that receives ciphertext information from the first terminal. The supervisory device uses its private key to decrypt the ciphertext and obtain the communication key, enabling monitoring without directly participating in the key negotiation between terminals. This mediator approach resolves the contradiction by allowing key acquisition for monitoring purposes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical key exchange mechanisms with cryptographic methods. Specifically, it uses public key infrastructure where the supervisory device has a public-private key pair. The first terminal encrypts the communication key using the supervisory device's public key, creating ciphertext that only the supervisory device can decrypt with its private key. This cryptographic substitution enables secure key delivery to the supervisory device.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If the supervisory device acquires the communication key through traditional methods, then monitoring can be enabled, but the system becomes vulnerable to man-in-the-middle attacks

Engineering Contradiction:
ImprovesecurityVSAvoidman-in-the-middle attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by having the first terminal verify the supervisory device's public key before encrypting the communication key. The terminal checks whether the public key belongs to a legitimate supervisory device, preventing unauthorized entities from intercepting the key. This pre-verification step counteracts potential man-in-the-middle attacks before they can occur.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent replaces insecure traditional key distribution mechanisms with public key cryptography. Instead of transmitting the communication key in plaintext or using vulnerable exchange protocols, the system uses asymmetric encryption where the supervisory device's public key secures the key transmission. This cryptographic substitution fundamentally strengthens security against interception and man-in-the-middle attacks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If the first terminal sends the communication key directly to the supervisory device in plaintext, then the supervisory device can monitor communications, but the key transmission becomes vulnerable to interception

Engineering Contradiction:
Improvemonitoring capabilityVSAvoidkey interception
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces plaintext key transmission with cryptographic encryption. The first terminal encrypts the communication key using the supervisory device's public key, transforming the plaintext key into ciphertext. This cryptographic substitution ensures that even if the transmission is intercepted, the key cannot be recovered without the supervisory device's private key, thus preventing key interception while maintaining monitoring capability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP4593322A1Key verification methods, key acquisition method, and devices
Publication Date: 2025.07.30 GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
  • EP4593322A1 patent drawingFigure 1~2
  • EP4593322A1 patent drawingFigure 3~5
  • EP4593322A1 patent drawingFigure 6~9

AI summary

Provided in the embodiments of the present application are key verification methods, a key acquisition method, and devices. On the basis of zero-knowledge proof information, a verification device can verify whether a private key of a supervisory device can decipher ciphertext information, and whether a key obtained by means of deciphering the ciphertext information is a communication key determined by means of a negotiation between a first terminal and a second terminal, thereby ensuring that after acquiring the ciphertext information, the supervisory device can decipher same to obtain the communication key determined by means of the negotiation between the first terminal and the second terminal, and then the supervisory device can monitor sidelink communication between the first terminal and the second terminal.