Multicast Key Management for IEEE 802.16n HR-Network Document Number: IEEE C802.16n-10/0012r1 Date Submitted: 2011-03-06 Source: Joseph Chee Ming Teo,

Slides:



Advertisements
Similar presentations
Mobility Consideration for E-MBS Document Number: IEEE C802.16m-08/584r1 Date Submitted: Source: Chun-Yen Wang, Chun-Yuan, Chiu, Fang-Ching (Frank)
Advertisements

M2M Task Group Closing Report (Session #78) [IEEE Mentor Presentation Template (Rev. 0)] Document Number: IEEE Gdoc Date Submitted:
IEEE MEDIA INDEPENDENT HANDOVER DCN: xx-00-sec Title: IEEE r Fast BSS Transition – A Study Date Submitted: September 21, 2009 Present.
IEEE MEDIA INDEPENDENT HANDOVER DCN: xx-00-sec Title: Initiate An Exercise for Generating a 21a Document Date Submitted: September 21, 2009.
Comments from on Proposed P802.21b PAR IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE /026r2 Date Submitted:
Multi-carrier Handover Method IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE C802.16m-08/1007r1 Date Submitted:
Document Number: Date Submitted: Source: Venue: Base Contribution: Purpose: Notice: This document does not represent the agreed views of the IEEE
1 Call-back HO Procedure for Reentry Femtocell Document Number: IEEE C802.16m-08/1438r1 Date Submitted: Source: Yung-Ting Lee, Hua-Chiang Yin.
Group-based M2M solutions Document Number: IEEE C802.16p-11/0013 Date Submitted: 2010/03/03 Source: Honggang Li, Rui Huang, Shantidev Mohant
Slide m HARQ Document Number: C802.16m-08/340 Date Submitted: Source: Sean McBeath, Juejun Liu, Jianmin LuVoice: Huawei Technologies
Access distribution for M2M devices Document Number: IEEE C802.16p-10_0028 Date Submitted: December 31, 2010 Source: Jin Lee, Youngsoo Yuk, Jeongki Kim,
1 Time Synchronization Methods for Femtocell Document Number: IEEE C802.16m-08/1323r1 Date Submitted: Source: Yung-Ting Lee, Hua-Chiang Yin.
Proposal of Different CRC Masks for Concatenated Subband Assignment A- MAP IEs ( ) Document Number: IEEE C802.16m-10/0041 Date Submitted:
-1- Management for M2M Devices [IEEE Presentation Submission Template (Rev. 9.2)] Document Number: IEEE C802.16p-10/0039 Date Submitted:
Session # NRR Committee Closing Report IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE /0040r1 Date Submitted:
DL/UL data transmission for M2M devices IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE C802.16p-10/0020 Date Submitted:
Project Planning Adhoc: WG Opening Plenary Report IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE /0022 Date Submitted:
21-07-xxxx IEEE MEDIA INDEPENDENT HANDOVER DCN: xxxx Title: Your Title Here Date Submitted: Month, NN, 200x Presented at IEEE.
Reduced Signaling Overhead for Retransmissions on the UL of m IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE S802.16m-07/250.
Adaptive Frequency Reuse in Project m SDD Document Number: S802.16m-07/203r1 Date Submitted: November 12, 2007 Source: I-Kang Fu
Service Continuity of Enhanced-MBS Document Number: IEEE C802.16m-08/1011 Date Submitted: Source: Chun-Yen Wang, Chun-Yuan, Chiu, Fang-Ching (Frank)
System Architecture Reference Model in n Document Number: IEEE S802.16gman-10/0048 Date Submitted: 2010/11/01 Source: Hung-Yu Wei, Ching-Chun Chou
Collaborative MIMO Based on Multiple Base Station Coordination IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE S802.16m-07/163,
MAC PDU Multiplexing Scheme for IEEE m Document Number: IEEE C802.16m-08/1015r1 Date Submitted: Source: Fang-Ching (Frank) Ren, Richard.
Optional retransmission schemes for E-MBS Document Number: IEEE S802.16m-08/1138 Date Submitted: Source: Ji LI, Yonggang WANG, Zhongji HU, Bijun.
Comment on Femto ABS Reliability ( ) IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE C802.16m-09/3095r2 Date Submitted:
Proposed texts to highlight Green Radio considerations for Hierarchical Networks design Document Number: IEEE C802.16PPC-11/0010.ppt Date Submitted:
Slides in support of the Proposed Text for Section E-MBS Configuration Indicators Document Number: IEEE S80216m-09_2779 Date Submitted:
Analysis of BR preamble selection strategies in 5-step BR procedure IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE C80216m-10_1249r1.
xxx IEEE MEDIA INDEPENDENT HANDOVER DCN: xxx Title: Proposal for adding a key hierarchy based approach in the security.
1 / 16 Differentiated Random Access Schemes Document Number: IEEE C802.16m-09/0620 Date Submitted: Source: Heejeong Cho
Report of the AWD compliance RG IEEE Presentation Submission Template (Rev. 9) Document Number: n Date Submitted: Source:
11/13/ Extremely Dense Access Networks as OmniRAN Use Case Document Number: IEEE Shet Date Submitted: Source: Claudio.
Omniran Network Detection and Selection Date: Authors: NameAffiliationPhone Max RiegelNSN
[Idle Mode Paging in Multicarrier] IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE C802.16m-09/0411r2 Date Submitted:
Security Support for Multi-cast Traffic in M2M communication Document Number: IEEE C802.16p-10/0022 Date Submitted: Source: Inuk Jung, Kiseon.
HR-MS Neighbor Discovery – Use Case 2: Out-of-coverage HR-MSs Discover Network Infrastructure Document Number: IEEE S802.16n-11/0098 Date Submitted:
Group based paging operation for p system IEEE Presentation Submission Template (Rev. 9.2) Document Number: IEEE C80216p-10_0018 Date Submitted:
Text Proposals of HR-MS Forwarding in 16n Network IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE S802.16n-11/0074 Date Submitted:
A Framework for HR-MS to HR-MS Direct Communication without Infrastructure Stations Document Number: IEEE S802.16n-10/0008 Date Submitted:
Security Support for Multi-cast Traffic in M2M communication Document Number: IEEE C802.16p-10/0032 Date Submitted: Source: Inuk Jung, Kiseon.
Text Proposals of PHY Frame and Physical Structure for 16n Direct Communication IEEE Presentation Submission Template (Rev. 9) Document Number:
Control Procedure for Direct Communication IEEE Presentation Submission Template (Rev. 9) Document Number: IEEE C802.16n-11/0054 Date Submitted:
A Proposal of HR-MS Direct Communication in IEEE n-GRIDMAN Network Document Number: IEEE S802.16n-11/0015r3 Date Submitted: Source: Ming-Tuo.
HR-MS Neighbor Discovery – Use Case 1: Registered HR-MSs Discover Each Other Document Number: IEEE S802.16n-11/0098 Date Submitted: Source:
HR-MS Neighbor Discovery in n Document Number: IEEE C802.16n-11/0021r2 Date Submitted: Source: Haiguang Wang, Hoang Anh Tuan, Jaya Shankar,
MM RG Report Document Number: IEEE C802.16n-11/0083 Date Submitted:
Reliable and Efficient Transmission to M2M Device Groups
Operational states for M2M device
Path discovery and management
Mesh Topology for Relays
Hoang Anh Tuan, Wang Haiguang, Jaya Shankar,
IEEE m SDD ToC for Inter RAT Handover
P802.16q Closing Report for Session #88
Protocol discussion Document Number: IEEE R0
Transmission Modes for Multi-Radio Access in Hierarchical Networks
Two-hop Operation to Relay Packets between Two TDC Links
Clarification of Burst-based Forwarding in RS Group
[place document title here]
HR-MS to HR-MS Synchronization in n
Working Group Treasurer’s Report - Session #100
[place document title here]
Further Considerations to MS-MS Power Control
Authenticated Validity for M2M devices
[IEEE Presentation Submission Template (Rev. 9.2)] Document Number:
IEEE MEDIA INDEPENDENT HANDOVER DCN: xx-00-sec
Inter-HR-BS Synchronization for n OFDMA Network
Working Group Treasurer’s Report - Session #106
Working Group Treasurer’s Report - Session #108
Text Proposals of PHY Control Structure for 16n Direct Communication
Presentation transcript:

Multicast Key Management for IEEE n HR-Network Document Number: IEEE C802.16n-10/0012r1 Date Submitted: Source: Joseph Chee Ming Teo, Jaya Shankar, Yeow Wai Leong, Hoang Anh Tuan, Zheng Shoukang, Mar Choon Hock Institute for Infocomm Research 1 Fusionopolis Way, #21-01, Connexis (South Tower) Singapore * Re: Call for contributions for n AWD Base Contribution: N/A Purpose: To be discussed and adopted by TG802.16n Notice: This document does not represent the agreed views of the IEEE Working Group or any of its subgroups. It represents only the views of the participants listed in the Source(s) field above. It is offered as a basis for discussion. It is not binding on the contributor(s), who reserve(s) the right to add, amend or withdraw material contained herein. Copyright Policy: The contributor is familiar with the IEEE-SA Copyright Policy. Patent Policy: The contributor is familiar with the IEEE-SA Patent Policy and Procedures: and..html#6sect6.html#6.3 Further information is located at and.

Introduction n SRD specifies requirement for Enhancements to Unicast and Multicast communication (Section 6.2.1) HR-Network shall provide optimized MAC protocols for unicast and multicast transmission to support applications of two-way communications such as Push to Talk (PTT) service among a group of HR-MS. Examples of applications to be used in PTT service include: audio (e.g., speech, music) video still image text (formatted and non-formatted) file transfer Use case scenario Public Protection and Disaster Relief (PPDR) Different Groups of Rescue teams (e.g. firemen and police officers) would have to communicate with each other without/without backbone networks Need for a common multicast key to encrypt/decrypt messages to prevent eavesdroppers or impersonation of legitimate multicast group members.

Introduction Multicast Key Management Existing – Multicast & Broadcast Rekeying Algorithm (MBRA) Research papers highlighted that MBRA does not provide forward secrecy and backward secrecy Forward secrecy – leaving users still able to decrypt secure multicast messages after leaving the group Backward secrecy – joining users can decrypt secure multicast messages sent before joining the group The n SRD specifies Section Multicast key Management HR-Network shall provide the security architecture that provides a group of HR-MSs with authentication, authorization, encryption and integrity protection. HR-Network shall provide multicast key management for the group of HR-MSs. The key shared within the group should be distributed securely and efficiently. HR-Network should support the group signaling procedure using multicast transmission for multicast key management efficiently.

Introduction Hence there is a need for enhanced multicast key management compared to MBRA. Multicast Key Management should address the forward and backward secrecy issue. Solution has to cover the various scenarios for secure multicast communication without/without infrastructure

Use Case Scenarios Initial Group Formation Controller node can be either HR-BS or an appointed HR- MS (Denoted as HR-MSX if HR-BS is not present)

Use Case Scenarios Join Event Currently not addressed by MBRA

Use Case Scenarios Leave Event Currently not addressed by MBRA

We proposed procedures for Initial Group Formation Join Event Leave Event Solution has to cover the various scenarios for secure multicast communication without/without infrastructure, i.e. solution has to be designed for Infrastructureless – PKI based Infrastructure – Pre-shared key based The controller can be either HR-BS (if present) or an appointed HR-MS (denoted HR-MSX) for PKI approach. Details of Contribution

Assumes that there is network infrastructure, i.e. each multicast member (HR-MSi) shares a unicast security key MSKi with the HR-BS. Initial Group Formation Procedure used to establish the Multicast key GTEK. Join and Leave Procedures used to update the GTEK to achieve backward and forward secrecy. Pre-shared key-based approach

Flow Diagram Initial Group Formation Procedure – Pre-shared key-based approach

Flow Chart Initial Group Formation Procedure – Pre-shared key approach

Initial Group Formation Procedure – Pre-shared key-based approach

Flow Diagram Join Procedure – Pre-shared key based approach

Flow Chart Join Procedure – Pre-shared key-based approach

Flow Diagram Leave Procedure – Pre-shared key-based approach

Flow Chart Leave Procedure – Pre-shared key-based approach

Leave Protocol – Pre-shared key-based approach

Uses the X.509 Certificates (defined in Standards ) Initial Group Formation Procedure used to establish the unicast security key MSKi (with each HR-MSi (multicast member) AND Multicast key GTEK. Join and Leave Procedures used to update the GTEK to achieve backward and forward secrecy. Also establish unicast security key MSKj with new joining nodes. PKI-based approach

Flow Diagram Initial Group Formation Procedure – PKI-based approach

Flow Chart Initial Group Formation Procedure – PKI-based approach HR-MSX/BS sends the multicast group information MulticastGrpInfo to all potential members of the multicast group comprising of HR-MSi for 1 <= i <= n Each HR-MSi generates nonce, computes the signature and sends Multicast_MSG_#1 to HR-MSX/BS. HR-MSX/BS verifies the received timestamps, nonce, messages and MACs. If the verifications are correct, HR-MSX/BS generates its nonce, the GTEK and MSKi for 1 <= i <= n and computes the MAC. HR-MSX/BS then encrypts the secret keys using each HR-MSis public key, computes the signatures for each message and sends Multicast_MSG_#2 to each HR-MSi. Each HR-MSi verifies the received timestamp, nonces and signature. If the verification is correct, each HR-MSi decrypts and obtains MSKi, GTEK and their lifetimes. Each HR-MSi then verifies the MAC and commence secure multicast if the verification is correct.

Initial Group Formation Procedure – PKI-based approach

Flow Diagram Join Procedure – PKI-based approach

Flow Chart Join Procedure – PKI-based approach

Flow Diagram Leave Procedure – PKI-based approach

Flow Chart Leave Procedure – PKI-based approach

GTEK Derivation Used to encrypt data packets for multicast service and shared amongst the HR-MSs in the multicast group Randomly generated by HR-MSX/BS or from the authentication server Shall be encrypted using HR-MSs public key, MSKi/MSKj pre-shared key or existing GTEK in the Join protocol. MSKi/MSKj Derivation Key shared between HR-MSi/HR-MSj with Controller HR- MSX/HR-BS. Used as an encryption key and MAC key Can be randomly generated by HR-MSX/BS in PKI- approach Pre-established in the pre-shared key approach Refreshed/rekeyed periodically to maintain key freshness. Key Derivation

Proposed text for IEEE802.16n AWD [ Start of Text Proposal ] Please refer to C80216n-11_0012r1.doc for proposed text. [ End of Text Proposal ]

Proposed new Multicast Key Management protocols for IEEE n networks Initial Group Formation Join Protocol Leave Protocol PKI-based approach Pre-shared key based approach Conclusion and Misc