Dynamic User Plane Integrity Protection in Wireless Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless networks lack effective integrity protection for user plane data, particularly in LTE systems, as existing solutions either provide insufficient protection against attacks or conflict with performance constraints such as latency and battery life, especially in low power wide area networks for IoT applications.

Innovation Solution

A system and method for dynamically enabling and disabling integrity protection for user plane data on a per data radio bearer (DRB) basis, using trigger conditions such as quality of service class identifiers and real-time monitoring to activate PDCP integrity protection only when necessary, reducing unnecessary resource consumption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If user plane integrity protection is applied continuously, then security against Man-In-The-Middle attacks is improved, but processing overhead and energy consumption increase

Engineering Contradiction:
Improveintegrity protectionVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements dynamic activation and deactivation of user plane integrity protection based on real-time trigger conditions. The integrity protection is not applied continuously but only when necessary, allowing the system to adapt between security and energy consumption requirements dynamically

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the operational state of integrity protection from a static continuous mode to a dynamic conditional mode. By monitoring trigger conditions and changing the protection state accordingly, the system optimizes the balance between security and energy consumption

Inventive Principle:
Principle #35Parameter changes

2Reliability

If user plane integrity protection is applied continuously, then security against data alteration attacks is improved, but processing overhead increases

Engineering Contradiction:
Improveintegrity protectionVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic activation and deactivation of user plane integrity protection based on real-time trigger conditions. The integrity protection is not applied continuously but only when necessary, allowing the system to adapt between security and processing overhead requirements dynamically

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the operational state of integrity protection from a static continuous mode to a dynamic conditional mode. By monitoring trigger conditions and changing the protection state accordingly, the system optimizes the balance between security and processing overhead

Inventive Principle:
Principle #35Parameter changes

3Reliability

If bearer level integrity protection is provided, then some security protection is achieved, but protection against rogue data insertion is insufficient

Engineering Contradiction:
Improvesecurity protectionVSAvoidrogue data insertion
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the data flow into different data radio bearers (DRBs), each with independent integrity protection control. This allows fine-grained security management where each bearer can be protected independently based on its specific security requirements and threat level

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system uses trigger conditions as feedback mechanisms to monitor network conditions and activate integrity protection when threats are detected. This feedback-driven approach enables the system to respond to actual security threats rather than applying protection uniformly

Inventive Principle:
Principle #23Feedback

4Reliability

If integrity protection is enabled for all data radio bearers, then comprehensive security is achieved, but resource consumption increases

Engineering Contradiction:
Improvecomprehensive securityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent applies local quality by enabling integrity protection selectively for specific data radio bearers based on their individual security requirements. Not all bearers receive the same treatment - only those with identified security risks get protection, optimizing resource allocation

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts which bearers receive integrity protection based on real-time trigger conditions. This dynamic approach allows the network to allocate resources efficiently by activating protection only when and where needed

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11637871B2System and method for dynamic activation and deactivation of user plane integrity in wireless networks
Publication Date: 2023.04.25 NOKIA OF AMERICA CORP
  • US11637871B2 patent drawing
  • US11637871B2 patent drawing
  • US11637871B2 patent drawing

AI summary

User equipment (UE) and a network node may establish data radio bearers (DRBs) for wireless communication of user plane data. For each DRB, the UE and network node may signal static integrity protection for the user plane data during set-up of the DRB. When the DRB has static integrity protection, integrity protection is applied to the user plane data for a duration of the DRB.