Encrypting Short Data Bursts in Wireless Idle Mode
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need for secure encryption of short data bursts in wireless communication systems, particularly in idle mode, to protect sensitive information such as personal and financial data transmitted via SMS, as existing technologies do not adequately address the security requirements for these messages.
Innovation Solution
A method and apparatus for encrypting short data bursts in wireless communication systems using a Traffic Encryption Key (TEK) derived from a Cipher-based Message Authentication Code (CMAC)-TEK prekey, which is generated from an Authorization Key (AK) related to the Security Association between a terminal and a Base Station, and utilizing a nonce identical to the uplink CMAC Packet Number (CMAC-PN_U) for integrity protection and encryption, ensuring secure transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing encryption technologies are used for short data bursts in idle mode, then the security of SMS data is insufficient, but implementing new encryption methods increases system complexity and signaling overhead
Solution Approach 1:
The patent applies universality by making the TEK serve multiple functions: it is used both for generating the CMAC digest (integrity protection) and for encrypting the short data burst (confidentiality). This multi-functionality eliminates the need for separate keys, reducing signaling overhead while maintaining strong security for SMS transmissions in idle mode.
Solution Approach 2:
The patent applies preliminary action by pre-generating the TEK from the CMAC-TEK prekey during the initial authentication phase (before idle mode transmission). This allows the terminal to have the encryption key ready in advance, enabling secure short data burst transmission without additional key exchange signaling during idle mode operations.
2Reliability
If a separate encryption key is used for short data bursts, then SMS security is improved, but signaling overhead increases
Solution Approach 1:
The patent makes the TEK universal by using it for both integrity protection (CMAC digest generation) and confidentiality (data encryption). This eliminates the need for a separate encryption key, thereby preventing additional signaling overhead while ensuring strong data confidentiality for short data bursts in idle mode.
Solution Approach 2:
The patent merges the functions of the integrity protection key and encryption key into a single TEK. By combining these two security functions into one key, the system avoids the signaling overhead associated with transmitting multiple separate keys while maintaining both confidentiality and integrity protection.
3Reliability
If encryption is implemented for short data in idle mode, then security is improved, but device complexity increases
Solution Approach 1:
The patent reduces device complexity by making the TEK multi-functional, serving both as the integrity protection key and encryption key. This eliminates the need for separate key management and handling logic in the terminal apparatus, simplifying the encryption apparatus while maintaining strong SMS security.
Solution Approach 2:
The terminal apparatus performs self-service by generating the TEK locally from the pre-shared CMAC-TEK prekey during initial authentication. This self-generated key approach eliminates the need for complex key distribution infrastructure and reduces device complexity while ensuring secure encryption capability for idle mode short data bursts.
Data Source
AI summary
A method and apparatus is capable of encrypting short data in a wireless communication system When a terminal generates a short data burst in idle mode, the apparatus generates a Traffic Encryption Key (TEK) using a Cipher-based Message Authentication Code (CMAC)-TEK prekey derived from an Authorization Key (AK) related to Security Association (SA) between the terminal and a Base Station (BS). A nonce is constructed with a Packet Number (PN) identical to an uplink CMAC PN (CMAC-PN_U) transmitted together with a Ranging Request (RNG-REQ) message carrying the short data burst The short data burst is encrypted using the TEK and the nonce. A Medium Access Control (MAC) Protocol Data Unit (PDU) is generated by attaching a MAC header and a CMAC digest for integrity protection to the RNG-REQ message carrying the encrypted short data burst. The MAC PDU is transmitted to the BS.


