Cooperative Layer Key for Secure Data Transmission

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cooperative communication processes, data transmitted between a benefited device and a base station through a supporting device is vulnerable to eavesdropping and tampering, as the supporting device cannot decrypt data encrypted with the benefited device's PDCP-layer key, compromising network security and reliability.

Innovation Solution

A method where the benefited device obtains a cooperative-layer key to encrypt uplink data, performs encapsulation, and sends the encrypted data to the supporting device in a short-distance communication mode, ensuring that only the benefited device can decrypt the data, and additional encryption and integrity protection are applied at the short-distance communication layer to prevent eavesdropping.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the supporting device uses the benefited device's PDCP-layer key to encrypt data, then data security is improved, but the supporting device cannot decrypt the data to forward it to the network device

Engineering Contradiction:
Improvedata securityVSAvoiddata forwarding capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the encryption key management into two distinct keys: a PDCP-layer key for encrypting user plane data and a cooperative-layer key for encrypting control plane data. This segmentation allows the supporting device to forward PDCP-layer encrypted data while using the cooperative-layer key for control plane data encryption, resolving the contradiction between security and forwarding capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The cooperative layer acts as an intermediary between the benefited device and the supporting device. It introduces a cooperative-layer key that enables secure communication between the benefiting device and network device while allowing the supporting device to forward data. The cooperative layer mediates the key management to ensure both security and forwarding functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If additional encryption and integrity protection are applied at the short-distance communication layer, then network security is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidencryption processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments security functions across different layers: the PDCP layer handles user plane data encryption, while the cooperative layer handles control plane data encryption and integrity protection. This segmentation distributes the complexity across multiple layers rather than concentrating it at one layer, making the overall system more manageable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different encryption and protection mechanisms are applied locally at different layers according to the specific requirements of each data type. The PDCP layer uses standard encryption for user plane data, while the cooperative layer uses integrity protection for control plane data, optimizing security without unnecessarily increasing complexity everywhere.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10027636B2Data transmission method, apparatus, and system
Publication Date: 2018.07.17 HUAWEI TECH CO LTD
  • US10027636B2 patent drawing
  • US10027636B2 patent drawing
  • US10027636B2 patent drawing

AI summary

The present invention relates to a data transmission method, apparatus, and system. The method includes: obtaining, by a benefited device, a cooperative-layer key, performing encryption, or encryption and integrity protection processing on uplink data by using the cooperative-layer key at a cooperative layer to obtain first encrypted data, performing encapsulation processing on the first encrypted data to obtain first encapsulated data, and sending the first encapsulated data to a supporting device in a short-distance communication mode, so that the supporting device processes the first encapsulated data to obtain second encapsulated data and sends the second encapsulated data to a base station. In embodiments of the present invention, secure data transmission is implemented between the benefited device, the supporting device, and the base station in a cooperative communication process, which improves network security and reliability of data transmission.