Inactive Terminal Secure Data Transmission via Security Context Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Inactive terminal devices in wireless communication systems cannot transmit data securely to a base station due to the lack of a Cell-Radio Network Temporary Identifier (C-RNTI) and the 'three-handshake' security activation mechanism, which is not guaranteed during rapid data transmission.

Innovation Solution

A method where a first device determines and transmits a message with transmission data and a security context identifier to a second device, allowing the second device to match and activate security for the inactive terminal device, ensuring secure data transmission by protecting the data with a security context that includes keys, encryption algorithms, or integrity-protection algorithms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the terminal device is in an inactive state to save power and enable rapid data transmission, then power consumption is reduced and data transmission speed is improved, but security activation cannot be guaranteed

Engineering Contradiction:
Improvedata transmission speedVSAvoidsecurity activation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The security context identifier is pre-configured and stored in the inactive terminal device before data transmission occurs. When the device needs to transmit data rapidly, the pre-stored security context identifier can be immediately used for security verification without requiring the three-handshake process, thus enabling both rapid transmission and security activation.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the three-handshake mechanism is used to activate security, then data transmission security is improved, but transmission latency increases

Engineering Contradiction:
Improvedata transmission securityVSAvoidtransmission latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The security context identifier is pre-configured and stored in the inactive terminal device before data transmission occurs. When the device needs to transmit data rapidly, the pre-stored security context identifier can be immediately used for security verification without requiring the three-handshake process, thus enabling both rapid transmission and security activation.

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If the terminal device does not allocate C-RNTI for air-interface transmission, then device complexity is reduced and power saving is improved, but the device cannot perform scheduled transmission

Engineering Contradiction:
Improveterminal device configurationVSAvoidair-interface scheduled transmission
Core Design Contradiction:
Device complexityVSEase of operation

Solution Approach 1:

The patent extracts the essential security verification function from the complete C-RNTI allocation and three-handshake process. By using only the security context identifier for security verification while maintaining the inactive state without full C-RNTI allocation, the solution separates security activation from full connection establishment, enabling rapid transmission with minimal configuration.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3493570B1Data transmission method, first device, and second device
Publication Date: 2021.01.20 CHINA ACAD OF TELECOMM TECH
  • EP3493570B1 patent drawingFigure 1~2
  • EP3493570B1 patent drawingFigure 3
  • EP3493570B1 patent drawingFigure 4

AI summary

A data transmission method, a first device, and a second device, for use in implementing secure data transmission between a terminal device in a non-active state and a base station. The method comprises: a first device determines a transmission message comprising transmission data and a secure context identifier of a terminal device, the terminal device being in a non-active state; the first device sends the transmission message to a second device; the second device matches the secure context identifier of the terminal device with a secure context identifier of at least one local terminal device, and determines, on the basis of the matching result, whether to activate the security of the terminal device.