Encrypting Short Data Bursts in Wireless Idle Mode

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for secure encryption of short data bursts in wireless communication systems, particularly in idle mode, to protect sensitive information such as personal and financial data transmitted via SMS, as existing technologies do not adequately address the security requirements for these messages.

Innovation Solution

A method and apparatus for encrypting short data bursts in wireless communication systems using a Traffic Encryption Key (TEK) derived from a Cipher-based Message Authentication Code (CMAC)-TEK prekey, which is generated from an Authorization Key (AK) related to the Security Association between a terminal and a Base Station, and utilizing a nonce identical to the uplink CMAC Packet Number (CMAC-PN_U) for integrity protection and encryption, ensuring secure transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing encryption technologies are used for short data bursts in idle mode, then the security of SMS data is insufficient, but implementing new encryption methods increases system complexity and signaling overhead

Engineering Contradiction:
ImproveSMS securityVSAvoidsystem overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by making the TEK serve multiple functions: it is used both for generating the CMAC digest (integrity protection) and for encrypting the short data burst (confidentiality). This multi-functionality eliminates the need for separate keys, reducing signaling overhead while maintaining strong security for SMS transmissions in idle mode.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent applies preliminary action by pre-generating the TEK from the CMAC-TEK prekey during the initial authentication phase (before idle mode transmission). This allows the terminal to have the encryption key ready in advance, enabling secure short data burst transmission without additional key exchange signaling during idle mode operations.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If a separate encryption key is used for short data bursts, then SMS security is improved, but signaling overhead increases

Engineering Contradiction:
Improvedata confidentialityVSAvoidsignaling overhead
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent makes the TEK universal by using it for both integrity protection (CMAC digest generation) and confidentiality (data encryption). This eliminates the need for a separate encryption key, thereby preventing additional signaling overhead while ensuring strong data confidentiality for short data bursts in idle mode.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the functions of the integrity protection key and encryption key into a single TEK. By combining these two security functions into one key, the system avoids the signaling overhead associated with transmitting multiple separate keys while maintaining both confidentiality and integrity protection.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If encryption is implemented for short data in idle mode, then security is improved, but device complexity increases

Engineering Contradiction:
ImproveSMS securityVSAvoidencryption apparatus
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent reduces device complexity by making the TEK multi-functional, serving both as the integrity protection key and encryption key. This eliminates the need for separate key management and handling logic in the terminal apparatus, simplifying the encryption apparatus while maintaining strong SMS security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The terminal apparatus performs self-service by generating the TEK locally from the pre-shared CMAC-TEK prekey during initial authentication. This self-generated key approach eliminates the need for complex key distribution infrastructure and reduces device complexity while ensuring secure encryption capability for idle mode short data bursts.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9088890B2Method and apparatus for encrypting short data in a wireless communication system
Publication Date: 2015.07.21 SAMSUNG ELECTRONICS CO LTD
  • US9088890B2 patent drawing
  • US9088890B2 patent drawing
  • US9088890B2 patent drawing

AI summary

A method and apparatus is capable of encrypting short data in a wireless communication system When a terminal generates a short data burst in idle mode, the apparatus generates a Traffic Encryption Key (TEK) using a Cipher-based Message Authentication Code (CMAC)-TEK prekey derived from an Authorization Key (AK) related to Security Association (SA) between the terminal and a Base Station (BS). A nonce is constructed with a Packet Number (PN) identical to an uplink CMAC PN (CMAC-PN_U) transmitted together with a Ranging Request (RNG-REQ) message carrying the short data burst The short data burst is encrypted using the TEK and the nonce. A Medium Access Control (MAC) Protocol Data Unit (PDU) is generated by attaching a MAC header and a CMAC digest for integrity protection to the RNG-REQ message carrying the encrypted short data burst. The MAC PDU is transmitted to the BS.