DRB Integrity Protection Check for User Plane Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In LTE and 5G NR systems, there is a lack of integrity protection for user plane data, making it difficult to prevent data tampering, and it is unclear how to determine if integrity protection fails and how to handle affected data.

Innovation Solution

An integrity protection method is implemented for data packets transmitted on a data radio bearer (DRB), which includes performing an integrity protection check and determining if the protection fails, with options to suspend or continue receiving data packets based on the check results, and configuring terminals and base stations to manage this process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If integrity protection is implemented for user plane data on DRB, then data security against tampering is improved, but device complexity and processing overhead increase

Engineering Contradiction:
Improvedata integrityVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-configuring integrity protection parameters (such as integrity protection enablement, algorithms, and verification thresholds) before data transmission begins. The terminal and base station establish integrity protection configurations in advance through RRC signaling, so that when user plane data needs to be transmitted, the integrity protection mechanism is already in place and ready to operate, avoiding complex real-time configuration decisions during data transfer

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements parameter changes by dynamically adjusting integrity protection related parameters based on data characteristics and network conditions. The base station can configure different integrity protection algorithms, enable/disable integrity protection for specific DRBs, and adjust verification thresholds according to the importance and sensitivity of the data being transmitted, thereby optimizing the balance between security and processing complexity

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If integrity protection check is performed on all data packets, then detection of tampered data is improved, but processing time and loss of time increase

Engineering Contradiction:
Improvetampering detection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies partial action by performing integrity protection checks selectively rather than on all data packets uniformly. The terminal can be configured to perform integrity verification on specific types of data packets, such as those containing sensitive information or critical control commands, while skipping verification on less critical data. This selective approach maintains high tampering detection accuracy for important data while reducing overall processing time

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent implements skipping by allowing the terminal to bypass integrity protection verification for certain data packets under specific conditions. When the data type is determined to be non-critical or when configured to trust certain data sources, the terminal can skip the integrity check process entirely, rushing through the verification step to minimize processing time while still maintaining security for important data

Inventive Principle:
Principle #21Skipping (Rushing through)

3Reliability

If DRB is suspended upon integrity protection failure, then prevention of processing tampered data is improved, but productivity and data transmission efficiency decrease

Engineering Contradiction:
Improvedata securityVSAvoiddata transmission efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies segmentation by dividing the DRB into multiple logical channels or data streams with different integrity protection policies. When integrity protection failure is detected in one segment or logical channel, only that specific segment is suspended or blocked, while other segments continue to transmit data normally. This granular approach prevents tampered data from affecting the entire data transmission system, maintaining productivity for unaffected data streams

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamics by making the DRB suspension decision adaptive rather than static. The terminal evaluates the severity and type of integrity protection failure, the importance of the affected data, and current network conditions before deciding whether to suspend the DRB. For minor failures or non-critical data, the terminal can choose to continue transmission with enhanced monitoring, while reserving suspension for severe failures affecting critical data, thereby dynamically balancing security and efficiency

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11570624B2Integrity protection method, terminal and base station
Publication Date: 2023.01.31 VIVO MOBILE COMM CO LTD
  • US11570624B2 patent drawing
  • US11570624B2 patent drawing
  • US11570624B2 patent drawing

AI summary

An integrity protection method, a terminal and a base station are provided. The integrity protection method, which is applied to a terminal, includes: performing an integrity protection check on data packets transmitted on a DRB, a split bearer corresponding to the DRB or a logical channel corresponding to the DRB, and determining whether an integrity protection of the DRB fails based on a result of the integrity protection check; and when it is determined that the integrity protection of the DRB fails, suspending the DRB or continuing receiving data packets carried by the DRB.