DRB Integrity Protection Check for User Plane Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In LTE and 5G NR systems, there is a lack of integrity protection for user plane data, making it difficult to prevent data tampering, and it is unclear how to determine if integrity protection fails and how to handle affected data.
Innovation Solution
An integrity protection method is implemented for data packets transmitted on a data radio bearer (DRB), which includes performing an integrity protection check and determining if the protection fails, with options to suspend or continue receiving data packets based on the check results, and configuring terminals and base stations to manage this process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If integrity protection is implemented for user plane data on DRB, then data security against tampering is improved, but device complexity and processing overhead increase
Solution Approach 1:
The patent applies preliminary action by pre-configuring integrity protection parameters (such as integrity protection enablement, algorithms, and verification thresholds) before data transmission begins. The terminal and base station establish integrity protection configurations in advance through RRC signaling, so that when user plane data needs to be transmitted, the integrity protection mechanism is already in place and ready to operate, avoiding complex real-time configuration decisions during data transfer
Solution Approach 2:
The patent implements parameter changes by dynamically adjusting integrity protection related parameters based on data characteristics and network conditions. The base station can configure different integrity protection algorithms, enable/disable integrity protection for specific DRBs, and adjust verification thresholds according to the importance and sensitivity of the data being transmitted, thereby optimizing the balance between security and processing complexity
2Measurement precision
If integrity protection check is performed on all data packets, then detection of tampered data is improved, but processing time and loss of time increase
Solution Approach 1:
The patent applies partial action by performing integrity protection checks selectively rather than on all data packets uniformly. The terminal can be configured to perform integrity verification on specific types of data packets, such as those containing sensitive information or critical control commands, while skipping verification on less critical data. This selective approach maintains high tampering detection accuracy for important data while reducing overall processing time
Solution Approach 2:
The patent implements skipping by allowing the terminal to bypass integrity protection verification for certain data packets under specific conditions. When the data type is determined to be non-critical or when configured to trust certain data sources, the terminal can skip the integrity check process entirely, rushing through the verification step to minimize processing time while still maintaining security for important data
3Reliability
If DRB is suspended upon integrity protection failure, then prevention of processing tampered data is improved, but productivity and data transmission efficiency decrease
Solution Approach 1:
The patent applies segmentation by dividing the DRB into multiple logical channels or data streams with different integrity protection policies. When integrity protection failure is detected in one segment or logical channel, only that specific segment is suspended or blocked, while other segments continue to transmit data normally. This granular approach prevents tampered data from affecting the entire data transmission system, maintaining productivity for unaffected data streams
Solution Approach 2:
The patent implements dynamics by making the DRB suspension decision adaptive rather than static. The terminal evaluates the severity and type of integrity protection failure, the importance of the affected data, and current network conditions before deciding whether to suspend the DRB. For minor failures or non-critical data, the terminal can choose to continue transmission with enhanced monitoring, while reserving suspension for severe failures affecting critical data, thereby dynamically balancing security and efficiency
Data Source
AI summary
An integrity protection method, a terminal and a base station are provided. The integrity protection method, which is applied to a terminal, includes: performing an integrity protection check on data packets transmitted on a DRB, a split bearer corresponding to the DRB or a logical channel corresponding to the DRB, and determining whether an integrity protection of the DRB fails based on a result of the integrity protection check; and when it is determined that the integrity protection of the DRB fails, suspending the DRB or continuing receiving data packets carried by the DRB.


