Base Station Security Processing for M2M Power Efficiency
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In machine-to-machine (M2M) communication, existing technologies face challenges in balancing security and low power consumption during data transmission between user equipment and base stations, particularly in the absence of access stratum security processing, which increases air interface signaling overheads and power consumption.
Innovation Solution
A security processing method where a base station receives security-processed data from user equipment, sends security request information to a core network device, and receives security response information, including security parameter information, to apply security protection on the air interface without increasing air interface signaling overheads, thereby ensuring secure data transmission while reducing power consumption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access stratum security protocol is used between UE and eNB to meet security requirement of RRC signaling, then security protection is improved, but air interface signaling overheads and terminal power consumption increase
Solution Approach 1:
The patent extracts the security processing function from the access stratum (AS) to the non-access stratum (NAS). Instead of performing security operations at the AS level between UE and eNB, the security processing is moved to the NAS level, where data is security-processed before being carried in NAS data packets. This eliminates the need for AS security protocols on the air interface, thereby reducing signaling overheads and power consumption while maintaining security protection.
Solution Approach 2:
The patent introduces an intermediary approach where security-processed data is embedded within NAS data packets (such as NAS PDU information elements) for transmission. The base station receives these security-processed data packets and forwards them to the core network device, which performs security deprocessing. This intermediary mechanism allows security protection without requiring AS security protocols on the air interface.
2Device complexity
If CP transmission solution is used to reduce signaling overheads, then air interface signaling overheads are reduced, but security protection capability is lost
Solution Approach 1:
The patent applies preliminary action by performing security processing on data before it is transmitted over the air interface. The data is security-processed at the UE side before being encapsulated in NAS data packets, ensuring that security protection is already in place before transmission. This allows the CP transmission solution to be used without compromising security, as the security function has already been applied in advance.
3Reliability
If AS security operation is performed to ensure security of data transmission, then security protection is improved, but terminal power consumption increases
Solution Approach 1:
The patent extracts the security operation from the terminal (UE) and relocates it to the network side (core network device). Instead of the terminal performing security operations on the air interface, the terminal only transmits security-processed data in NAS packets. The actual security deprocessing is performed by the base station forwarding to the core network device, thereby eliminating terminal power consumption for AS security operations while maintaining data transmission security.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Embodiments of the present invention disclose a security processing method and a related device. The method may include: receiving, by a base station, security-processed target data sent by user equipment UE; sending, by the base station, security request information of the UE to a core network device; and receiving, by the base station, security response information returned by the core network device, where the security response information includes security parameter information of the UE and/or security-deprocessed target data. According to the present invention, during data transmission between the UE and the base station, not only data security can be ensured, but also low power consumption can be ensured.