Dynamic-Length Physical-Layer Ciphering for Transport-Block Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication networks face security vulnerabilities due to unciphered data in transport blocks, such as L2 headers and IP headers, which can be exploited by attackers to discover traffic patterns and disrupt connections.
Innovation Solution
A method for dynamic length security in the physical layer that evaluates TB size and either fully ciphers smaller TBs or partially ciphers larger TBs, targeting unciphered data portions, using ciphering control information to ensure secure transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the entire transport block is ciphered, then data security is improved, but hardware requirements and processing complexity increase
Solution Approach 1:
The transport block is segmented into different portions: already ciphered data (IP payload) and unciphered data (L2 headers, IP headers). The invention applies full ciphering only to the unciphered portions while leaving the already ciphered portions unchanged, thus segmenting the ciphering operation to reduce hardware requirements while maintaining security.
Solution Approach 2:
Different parts of the transport block receive different treatment: the unciphered portions (L2 headers, IP headers) receive full ciphering protection, while the already ciphered portions (IP payload) remain unchanged. This local differentiation applies ciphering quality selectively where needed, reducing overall hardware burden.
2Reliability
If the entire transport block is ciphered, then data security is improved, but processing time increases
Solution Approach 1:
The ciphering operation is segmented to only process the unciphered portions of the transport block (L2 headers, IP headers) rather than the entire block. This segmentation reduces the processing time required while maintaining security for the vulnerable unciphered data.
Solution Approach 2:
Instead of applying full ciphering to the entire transport block (excessive action), the invention applies partial ciphering only to the necessary unciphered portions. This partial action reduces processing time while providing adequate security protection.
3Device complexity
If partial ciphering is performed, then hardware requirements are reduced, but security coverage is worsened
Solution Approach 1:
Full ciphering protection is applied locally to the unciphered portions (L2 headers, IP headers) where security is most needed, while the already ciphered IP payload remains unchanged. This localized approach ensures adequate security coverage for vulnerable data without requiring full-block ciphering hardware.
4Reliability
If full ciphering is applied to large transport blocks, then security is improved, but processing efficiency decreases
Solution Approach 1:
The transport block is segmented into ciphered and unciphered portions. Full ciphering is applied only to the unciphered portions (L2 headers, IP headers), while the already ciphered IP payload is processed efficiently without additional ciphering operations, thus maintaining high processing efficiency for large blocks.
Solution Approach 2:
Partial ciphering is applied to large transport blocks, ciphering only the necessary unciphered portions rather than the entire block. This partial action maintains processing efficiency by avoiding redundant ciphering operations on already encrypted data.
Data Source
AI summary
Methods, apparatuses, systems, and computer programs for ciphering information in a physical layer of a wireless communications network are disclosed. In one aspect, a method can include obtaining, by a UE, a transport block for transmission using the physical layer, determining, by the UE, whether the size of the transport block satisfies a predetermined threshold, and based on a determination, by the UE, that the size of the transport block satisfies a predetermined threshold size: ciphering, by the UE, the entire transport block, and transmitting, by the UE and to an access node, the ciphered transport block using the physical layer.


