Link Layer Encryption Initialization Vector Interleaving
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication systems, such as those following the P25 standard, face challenges in efficiently implementing link layer encryption for voice message streams, particularly when end-to-end encryption is already in use, leading to delays and truncation issues due to insufficient signalling space and dynamic encryption management.
Innovation Solution
A method and system that enable dynamic link layer encryption for both end-to-end encrypted and non-end-to-end encrypted voice message streams by reusing or generating encryption initialization vectors, allowing for seamless integration with existing protocols without additional signalling overhead, and interleaving link layer and end-to-end encryption to minimize delays and truncation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If link layer encryption is implemented on voice message streams that already have end-to-end encryption, then security is enhanced, but delays and truncation occur due to insufficient signalling space and processing overhead
Solution Approach 1:
The system dynamically determines whether to generate a new encryption initialization vector or reuse an existing one based on the encryption status of the voice message stream. This dynamic adaptation allows the base station to optimize processing efficiency while maintaining enhanced security through link layer encryption.
Solution Approach 2:
The encryption initialization vector parameter is changed or reused based on the specific encryption requirements of the voice message stream. By modifying this parameter dynamically, the system achieves link layer encryption without incurring significant processing delays or truncation.
2Reliability
If link layer encryption is added to existing end-to-end encrypted streams, then encryption management becomes more complex, but protocol compliance is maintained
Solution Approach 1:
The base station is designed to handle multiple encryption scenarios (end-to-end encrypted and non-end-to-end encrypted voice message streams) using a unified approach. It can dynamically determine the encryption status and apply appropriate link layer encryption, making the system multi-functional and adaptable to different encryption requirements while maintaining protocol compliance.
3Productivity
If encryption initialization vectors are dynamically generated and reused, then processing efficiency improves, but encryption security could be compromised
Solution Approach 1:
The system dynamically determines whether to generate a new encryption initialization vector or reuse an existing one based on the specific encryption requirements of each voice message stream. This dynamic decision-making process optimizes processing efficiency while maintaining encryption security by applying link layer encryption appropriately without unnecessary vector generation.
Data Source
AI summary
Methods and systems for LLE encrypting and decrypting voice message streams (VMSs) already supporting eTe encryption are disclosed. In one example, LLE and eTe encryption initialization vectors (EIVs) are interleaved such that an LLE EIV retrieved from one of a header and a data unit is used to LLE decrypt both the header or data unit and a subsequent data unit. A recovered eTe EIV is used to eTe decrypt voice payloads in one or more subsequent data units. In another example, a base station dynamically LLE encrypts a VMS already supporting eTe encrypting by determining whether a received VMS is eTe encrypted, and ii it is not generating a new LLE EIV, and if it is, re-using the pre-existing eTe EIV for LLE encryption. The LLE encrypted (and perhaps eTe encrypted) VMS is then sent over the air to one or more mobile stations.


