AT Command for Secure ESM Information Transmission

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In LTE networks, there is a challenge in determining whether Evolved Packet System (EPS) Session Management (ESM) information should be ciphered, leading to ambiguity in setting the ESM information transfer flag and potential security issues during transmission.

Innovation Solution

The introduction of dedicated AT commands, such as +CGSPTESMI and +CGDCONT, which allow Terminal Equipment (TE) to indicate whether Protocol Configuration Options (PCO) and Access Point Name (APN) should be transmitted securely, enabling the Mobile Termination (MT) to set the ESM information transfer flag appropriately and ensure secure transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dedicated AT commands are introduced to indicate secure transmission requirements, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces dedicated AT commands as an intermediary communication mechanism between the Terminal Equipment (TE) and Mobile Termination (MT). These commands serve as a mediator to convey security requirements (ciphering needs for ESM information) from the application layer to the modem layer, resolving the contradiction by providing a structured interface that improves security reliability while managing complexity through standardized command syntax.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the ESM information transfer flag is set to ensure secure transmission, then security protection is improved, but transmission efficiency deteriorates due to additional processing

Engineering Contradiction:
Improvesecurity protectionVSAvoidtransmission efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by having the TE indicate security requirements through AT commands before the actual ESM information transmission occurs. The MT uses this advance notice to pre-configure ciphering settings and set the ESM information transfer flag appropriately, ensuring security protection is in place before data transmission begins, thereby avoiding mid-transmission processing delays.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If ciphering is applied to ESM information transmission, then security is improved, but processing complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security management function into a separate, dedicated AT command interface. Instead of embedding complex security decision logic within the general data transmission pathway, the security requirements are extracted and handled through specific +CGSPTESMI and +CGDCONT commands, allowing the main transmission process to remain simple while security processing is handled by a specialized subsystem.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10165445B2AT command for secure ESM information
Publication Date: 2018.12.25 APPLE INC
  • US10165445B2 patent drawing
  • US10165445B2 patent drawing
  • US10165445B2 patent drawing

AI summary

Systems and methods for transmitting AT commands indicating whether Evolved Packet System (EPS) Session Management (ESM) information should be transmitted securely are disclosed herein. A Terminal Equipment (TE) may transmit an AT command to a Mobile Termination (MT). The AT command may indicate whether protocol configuration options (PCO) should be ciphered and/or whether an access point name (APN) is provided. In some embodiments, the AT command may be a dedicated command and may only include a <securePCO> parameter and an <APNprovided> parameter. Alternatively, or in addition, the AT command may include a <securePCO> parameter, an <APN> parameter, and/or additional parameters serving additional functions. Whether the APN is provided may be determined based on whether the <APN> parameter is present and includes a non-null value. The AT command may be related to a single packet data network (PDN) connection or may relate to a plurality of PDN connections.