Description
The Group Management Key (GMK) is a fundamental security credential in 3GPP architectures, specifically designed to protect group-based services. It is a symmetric cryptographic key that is shared among all legitimate members of a group and trusted network entities, such as the Group Management Server (GMS) or ProSe Function. The GMK serves as a root key for deriving other security keys used for various protection functions, including authentication between group members and the network, integrity protection of group management signaling, and encryption of group communication traffic. Its management lifecycle—generation, distribution, storage, and revocation—is critical to the security of services like Mission Critical Push-to-Talk (MCPTT), Proximity Services (ProSe) direct communication, and IoT group messaging.
Architecturally, the GMK is typically generated by a central authority within the network, such as the GMS residing in the home network or a dedicated Key Management Center. For ProSe, the ProSe Function may generate the GMK. The key is then securely distributed to each group member's UE via protected signaling channels, often using individual subscriber keys for over-the-air encryption during distribution. Once stored in the UE's secure environment (e.g., in the Group Management Client), the GMK is used to derive session-specific keys, such as the Group Traffic Key (GTK) for encrypting user plane data or the Group Integrity Key (GIK) for protecting control messages. This key hierarchy ensures that compromise of a derived session key does not expose the root GMK.
The operation of GMK involves several protocols and interfaces. For example, in MCPTT, when a UE joins a group, the GMS authenticates the UE and then provisions the GMK (or a key-encrypting key to deliver the GMK) to the UE's GMC. The specifications detail key derivation functions (KDFs) that use the GMK along with other parameters like group identifiers and sequence numbers to produce fresh keys. The GMK is also periodically updated or rekeyed by the network to maintain forward and backward secrecy, especially when group membership changes. In ProSe scenarios, the GMK may enable direct secure communication between UEs without network infrastructure, using the key for mutual authentication and encryption over the PC5 reference point.
Purpose & Motivation
The GMK was introduced to address the lack of standardized, secure key management for group communications in cellular networks, a gap that became critical with the standardization of Mission Critical Services and ProSe in Release 12. Prior to this, group services either used insecure methods or relied on application-layer security that was not integrated with network authentication, making them vulnerable to eavesdropping, impersonation, and replay attacks. The need for secure, low-latency group communications for public safety and critical infrastructure demanded a network-level security solution.
The creation of the GMK provides a unified cryptographic foundation for group security within the 3GPP framework. It solves the problem of scalable and efficient key distribution for dynamic groups by defining a centralized key management architecture. This allows the network to control group membership cryptographically; only UEs possessing the valid GMK can participate in secure group communications. It addresses limitations of pairwise keying, which would require a separate key for each pair of members and does not scale for large groups.
Historically, security in cellular networks focused primarily on individual subscriber authentication (e.g., using Ki in SIM cards). The GMK extends this paradigm to groups, enabling new service models. Its design was motivated by requirements from public safety organizations for secure push-to-talk and proximity-based communication during emergencies. By integrating with existing 3GPP security frameworks like the Authentication and Key Agreement (AKA), the GMK ensures that group security leverages the robust subscriber authentication already in place, while adding the necessary group-oriented key management to support both network-based and direct device-to-device communication scenarios.
Classification
Release Timeline
Detected Changes Across Releases
from 3GPP Change RequestsSpecific changes extracted from the „Change history“ tables of 3GPP specifications (1 CRs across 1 releases). Complements the general historical overview above with the evidence-based evolution of this function.
In Release 15, the primary new introduction for the GMK function was a clarification of its management procedures. This clarification specifically addressed the role of the Group Management Server (GMS) in originating the Group Master Key (GMK) and its secure, individual transfer to group members. The update ensured that authorized users, such as those performing discreet listening in Mission Critical services, could obtain the GMK without violating end-to-end encryption requirements for the group.
- GMK management clarification TS 33.180CR0054
Explore further
Broader topics and technologies where GMK plays a role.
Defining Specifications
3GPP specifications that define or reference GMK, with the latest known release. Sourced from the 3GPP document catalog — see methodology.
| Specification | Title | Release |
|---|---|---|
| TS 23.784 vg00 | Discreet Listening for Mission Critical Services | Rel-16 |
| TS 24.380 vj10 | MCPTT Media Plane Control Protocol | Rel-19 |
| TS 24.581 vj00 | MCVideo Media Plane Control Protocol Specification | Rel-19 |
| TS 24.582 vj00 | MCData Media Plane Control Protocols | Rel-19 |
| TS 29.380 vj00 | MCPTT-LMR Interworking Media Plane Control | Rel-19 |
| TS 29.582 vj00 | MCData Interworking with LMR Systems | Rel-19 |
| TS 33.179 vdc0 | MCPTT Security Architecture and Procedures | Rel-13 |
| TS 33.180 vk00 | Security of Mission Critical (MC) Service | Rel-20 |
| TS 33.303 vj00 | ProSe Security Specification for EPS | Rel-19 |
| TS 33.879 vd10 | MCPTT Security Study | Rel-13 |
| TS 33.880 vf10 | Security Study for Enhanced Mission Critical Services | Rel-15 |
| TR 33.938 vj10 | 3GPP Cryptographic Inventory for 5G | Rel-19 |