Security for prose group communication
Abstract
A method of performing authentication and authorization in Proximity based Service (ProSe) communication by a requesting device ( 31 ) which sends a request of a communication and a receiving device ( 32 ) which receives the request from the requesting device ( 31 ) and ( 32 ), the method including deriving session keys Kpc and Kpi from an unique key Kp at the requesting and receiving devices ( 31 ) and ( 32 ), using the session keys Kpc and Kpi for ProSe communication setup and direct communication between the requesting and receiving devices ( 31 ) and ( 32 ), starting the direct communication with the requesting and receiving devices ( 31 ) and ( 32 ). The key Kpc is confidentiality key and the key Kpi is integrity protection key.
Claims
exact text as granted — not AI-modified1 . A method of performing authentication and authorization in Proximity based Service (ProSe) communication by a requesting device which sends a request of a communication and a receiving device which receives the request from the requesting device, the method comprising:
deriving session keys Kpc and Kpi from an unique key Kp at the requesting and receiving devices; using the session keys Kpc and Kpi for ProSe communication setup and direct communication between the requesting and receiving devices; and starting the direct communication with the requesting and receiving devices, wherein the key Kpc is confidentiality key and the key Kpi is integrity protection key.
2 . The method of performing authentication and authorization in ProSe communication according to claim 1 further comprising:
requesting a ProSe service request to the ProSe server from the requesting device;
performing a discovery procedure by the ProSe server to obtain location information of the receiving device; and
sending a ProSe service result to the requesting and receiving devices,
wherein the key Kp is sent from the ProSe Server to the requesting and receiving devices in the ProSe service result.
3 . The method of performing authentication and authorization in ProSe communication according to claim 2 ,
wherein the direct communication is one-to-one communication between the requesting and receiving devices.
4 . The method of performing authentication and authorization in ProSe communication according to claim 2 ,
wherein the direct communication is one-to-many communication between the requesting device and a plurality of the receiving devices in a same group, and wherein the requesting device can send broadcasting messages to other receiving devices in the same group, and other devices can send broadcasting messages to the requesting device but cannot send broadcasting messages each other.
5 . The method of performing authentication and authorization in ProSe communication according to claim 1 further comprising:
sending the key Kp from the ProSe Server when the requesting and receiving devices are registered to the ProSe Server;
requesting a ProSe service request to the ProSe server from the requesting device;
performing a discovery procedure by the ProSe server to obtain location information of the receiving device; and
sending device ID list of allowed receiving devices, service ID in a ProSe service result to the requesting device.
6 . The method of performing authentication and authorization in ProSe communication according to claim 2 ,
wherein the direct communication is one-to-many communication between the requesting device and a plurality of the receiving devices in a same group, and wherein the requesting device can send broadcasting messages to other receiving devices in the same group, and other devices can send broadcasting messages to the requesting device as well as each other.
7 . A secure system including a plurality of User Equipments (UEs), and a Proximity based Service (ProSe) server comprising:
a requesting device which sends a request of a communication; and a receiving device which receives the request from the requesting device, wherein the requesting and receiving devices derive session keys Kpc and Kpi from an unique key Kp; the requesting and receiving devices use the session keys Kpc and Kpi for ProSe communication setup and direct communication between the requesting and receiving devices; and the requesting and receiving devices start the direct communication with the requesting and receiving devices, wherein the key Kpc is confidentiality key and the key Kpi is integrity protection key.Join the waitlist — get patent alerts
Track US2016149876A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.