Zero-Knowledge Key Verification for UE-to-UE Sidelink Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Supervisory devices in 3GPP communication systems lack the capability to monitor UE to UE relay scenarios, as existing key negotiation protocols like DH (Diffie-Hellman) are vulnerable to attacks and do not facilitate key acquisition by the supervisory device.
Innovation Solution
Implement a key verification method using zero-knowledge proof to ensure that a supervisory device can decrypt ciphertext information and obtain the communication key determined by terminals, enabling monitoring in UE to UE relay scenarios.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional key negotiation protocols (e.g., Diffie-Hellman) are used in UE to UE relay scenarios, then key exchange between terminals can be achieved, but the supervisory device cannot acquire the communication key for monitoring
Solution Approach 1:
The patent introduces a supervisory device as an intermediary that receives ciphertext information from the first terminal. The supervisory device uses its private key to decrypt the ciphertext and obtain the communication key, enabling monitoring without directly participating in the key negotiation between terminals. This mediator approach resolves the contradiction by allowing key acquisition for monitoring purposes.
Solution Approach 2:
The patent replaces traditional mechanical key exchange mechanisms with cryptographic methods. Specifically, it uses public key infrastructure where the supervisory device has a public-private key pair. The first terminal encrypts the communication key using the supervisory device's public key, creating ciphertext that only the supervisory device can decrypt with its private key. This cryptographic substitution enables secure key delivery to the supervisory device.
2Reliability
If the supervisory device acquires the communication key through traditional methods, then monitoring can be enabled, but the system becomes vulnerable to man-in-the-middle attacks
Solution Approach 1:
The patent applies preliminary anti-action by having the first terminal verify the supervisory device's public key before encrypting the communication key. The terminal checks whether the public key belongs to a legitimate supervisory device, preventing unauthorized entities from intercepting the key. This pre-verification step counteracts potential man-in-the-middle attacks before they can occur.
Solution Approach 2:
The patent replaces insecure traditional key distribution mechanisms with public key cryptography. Instead of transmitting the communication key in plaintext or using vulnerable exchange protocols, the system uses asymmetric encryption where the supervisory device's public key secures the key transmission. This cryptographic substitution fundamentally strengthens security against interception and man-in-the-middle attacks.
3Reliability
If the first terminal sends the communication key directly to the supervisory device in plaintext, then the supervisory device can monitor communications, but the key transmission becomes vulnerable to interception
Solution Approach 1:
The patent replaces plaintext key transmission with cryptographic encryption. The first terminal encrypts the communication key using the supervisory device's public key, transforming the plaintext key into ciphertext. This cryptographic substitution ensures that even if the transmission is intercepted, the key cannot be recovered without the supervisory device's private key, thus preventing key interception while maintaining monitoring capability.
Data Source
Figure 1~2
Figure 3~5
Figure 6~9
AI summary
Provided in the embodiments of the present application are key verification methods, a key acquisition method, and devices. On the basis of zero-knowledge proof information, a verification device can verify whether a private key of a supervisory device can decipher ciphertext information, and whether a key obtained by means of deciphering the ciphertext information is a communication key determined by means of a negotiation between a first terminal and a second terminal, thereby ensuring that after acquiring the ciphertext information, the supervisory device can decipher same to obtain the communication key determined by means of the negotiation between the first terminal and the second terminal, and then the supervisory device can monitor sidelink communication between the first terminal and the second terminal.