Dynamic User Plane Integrity Protection in Wireless Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless networks lack effective integrity protection for user plane data, particularly in LTE systems, as existing solutions either provide insufficient protection against attacks or conflict with performance constraints such as latency and battery life, especially in low power wide area networks for IoT applications.
Innovation Solution
A system and method for dynamically enabling and disabling integrity protection for user plane data on a per data radio bearer (DRB) basis, using trigger conditions such as quality of service class identifiers and real-time monitoring to activate PDCP integrity protection only when necessary, reducing unnecessary resource consumption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If user plane integrity protection is applied continuously, then security against Man-In-The-Middle attacks is improved, but processing overhead and energy consumption increase
Solution Approach 1:
The patent implements dynamic activation and deactivation of user plane integrity protection based on real-time trigger conditions. The integrity protection is not applied continuously but only when necessary, allowing the system to adapt between security and energy consumption requirements dynamically
Solution Approach 2:
The system changes the operational state of integrity protection from a static continuous mode to a dynamic conditional mode. By monitoring trigger conditions and changing the protection state accordingly, the system optimizes the balance between security and energy consumption
2Reliability
If user plane integrity protection is applied continuously, then security against data alteration attacks is improved, but processing overhead increases
Solution Approach 1:
The patent implements dynamic activation and deactivation of user plane integrity protection based on real-time trigger conditions. The integrity protection is not applied continuously but only when necessary, allowing the system to adapt between security and processing overhead requirements dynamically
Solution Approach 2:
The system changes the operational state of integrity protection from a static continuous mode to a dynamic conditional mode. By monitoring trigger conditions and changing the protection state accordingly, the system optimizes the balance between security and processing overhead
3Reliability
If bearer level integrity protection is provided, then some security protection is achieved, but protection against rogue data insertion is insufficient
Solution Approach 1:
The patent segments the data flow into different data radio bearers (DRBs), each with independent integrity protection control. This allows fine-grained security management where each bearer can be protected independently based on its specific security requirements and threat level
Solution Approach 2:
The system uses trigger conditions as feedback mechanisms to monitor network conditions and activate integrity protection when threats are detected. This feedback-driven approach enables the system to respond to actual security threats rather than applying protection uniformly
4Reliability
If integrity protection is enabled for all data radio bearers, then comprehensive security is achieved, but resource consumption increases
Solution Approach 1:
The patent applies local quality by enabling integrity protection selectively for specific data radio bearers based on their individual security requirements. Not all bearers receive the same treatment - only those with identified security risks get protection, optimizing resource allocation
Solution Approach 2:
The system dynamically adjusts which bearers receive integrity protection based on real-time trigger conditions. This dynamic approach allows the network to allocate resources efficiently by activating protection only when and where needed
Data Source
AI summary
User equipment (UE) and a network node may establish data radio bearers (DRBs) for wireless communication of user plane data. For each DRB, the UE and network node may signal static integrity protection for the user plane data during set-up of the DRB. When the DRB has static integrity protection, integrity protection is applied to the user plane data for a duration of the DRB.


