Configured Grant Uplink Authentication Before Subsequent Data Transmission
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In configured grant (CG)-small data transmission (SDT), user equipment (UE) may transmit subsequent data before network identity authentication is successful, leading to unauthorized data reception by the network.
Innovation Solution
Implementing a method where the UE transmits first uplink data containing identity authentication information on a first CG resource, followed by a duration or timer, ensuring subsequent data transmission only after network authentication is completed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the UE transmits subsequent data immediately using CG resources, then data transmission efficiency is improved, but network security deteriorates due to potential unauthorized data reception before authentication
Solution Approach 1:
The patent applies preliminary action by requiring the UE to transmit identity authentication information (such as resume MAC-I) in the first uplink data before any subsequent data transmission. The network device performs authentication verification on this information beforehand, ensuring that only authenticated UEs can transmit subsequent data on CG resources, thus preventing unauthorized data reception while maintaining transmission efficiency.
2Reliability
If the network performs identity authentication before receiving subsequent data, then network security is improved, but data transmission delay increases
Solution Approach 1:
The patent implements preliminary authentication by having the UE include identity authentication information in the first uplink data transmission. The network device verifies the authentication information (resume MAC-I) generated by the UE using the stored key and previous message authentication code. This preliminary verification ensures that authentication is completed before subsequent data transmission, preventing security breaches without causing delays.
3Reliability
If the UE includes identity authentication information in the first uplink data, then network security is improved, but message overhead increases
Solution Approach 1:
The patent merges identity authentication information with the first uplink data transmission by including the resume MAC-I within the same message structure. Instead of sending separate authentication packets, the authentication information is integrated into the RRC resume request or other uplink data messages, thereby verifying UE identity without significantly increasing overall message overhead.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A data transmission method and related apparatuses are provided. The method includes the following. A terminal device transmits first uplink data on a first configured grant (CG) resource, where the first uplink data contains first information, and the first information is used for identity authentication of the terminal device. After a first duration elapsed, the terminal device transmits second uplink data on a second CG resource. In this way, by setting the first duration, it is possible to ensure that the terminal device can transmit the second uplink data only after a network performs identity authentication on the terminal device, thereby avoiding receiving subsequent data by the network before performing identity authentication on a user equipment (UE) during CG-small data transmission (SDT).