Air Interface Protection Key for Wireless Session Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In wireless communication systems, especially in LTE, intermediate nodes can intercept and read session information from protocol data units, compromising security as end-to-end protection mechanisms typically only encrypt payload data, leaving session identifiers and headers unprotected.
Innovation Solution
A method where user equipment (UE) and access network devices (AN) negotiate an air interface protection key to encrypt session identifying information in protocol data units, ensuring that only the UE and AN can decrypt this information, preventing intermediate nodes from accessing it.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If end-to-end protection mechanism is used to encrypt payload data, then security against eavesdropping by intermediate nodes is improved, but session identifying information in headers remains unprotected and can be intercepted
Solution Approach 1:
The protocol data unit is divided into two parts: payload data and header information. Different encryption approaches are applied to each part - the payload uses end-to-end encryption while the header uses link-layer encryption with the access network device. This segmentation allows simultaneous protection of both data confidentiality and session identification security.
Solution Approach 2:
Different encryption mechanisms are applied to different parts of the data structure based on their specific security requirements. The payload field receives end-to-end encryption suitable for confidential data, while the header field receives link-layer encryption appropriate for session management information. This local quality approach optimizes security for each component's specific needs.
2Reliability
If all information in session is encrypted segment by segment, then transmission security is improved, but intermediate nodes cannot read session information needed for routing and forwarding
Solution Approach 1:
The data transmission is segmented into payload and header components, each encrypted with appropriate mechanisms. The header contains session information encrypted with link-layer keys that intermediate nodes can decrypt for routing purposes, while the payload remains end-to-end encrypted. This segmentation resolves the contradiction between security and routing functionality.
Solution Approach 2:
The access network device acts as an intermediary that holds link-layer encryption keys. It can decrypt header information for routing decisions while forwarding the encrypted payload unchanged to the core network. This intermediary approach enables intermediate nodes to perform routing without compromising end-to-end payload security.
3Ease of operation
If session identifiers are left unencrypted for intermediate node reading, then routing functionality is maintained, but attackers can intercept and track sessions
Solution Approach 1:
The header information receives link-layer encryption specifically tailored for protecting session identifiers during air interface transmission. This local quality approach applies encryption only where needed (in the header) without preventing intermediate nodes from accessing routing information through their security context, thus protecting against attackers while maintaining routing functionality.
Data Source
AI summary
Embodiments of the present invention disclose a data transmission method and a related device and system. The system includes an access network device AN and user equipment UE. The AN is configured to receive a base key sent by a key management device in a core network, where the base key is a key generated from two-way authentication between the UE and the core; the AN and the UE are configured to process the base key according to a preset rule to generate an air interface protection key; the UE is configured to: protect a target field in an uplink protocol data unit PDU by using the air interface protection key; and the AN is configured to parse the target field in the uplink protocol data unit by using the air interface protection key.


