Integrity Protection Failure Handling in LTE-NR Dual Connectivity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the transition to 5G mobile communication, the integration of LTE and NR networks faces challenges due to limited spectrum availability below 6 GHz, leading to security risks from malicious data alterations during integrity protection verification failures in data radio bearers, which can compromise communication security and data transmission success rates.
Innovation Solution
A method is introduced where network devices obtain and send indication information when integrity protection verification fails, allowing for updating the secret key or releasing the RRC connection of a data radio bearer, thereby ensuring communication security and improving data transmission success rates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If integrity protection verification is implemented on data radio bearer in NR, then communication security is improved, but data transmission success rate deteriorates due to malicious data alterations being discarded
Solution Approach 1:
The patent implements a feedback mechanism where the network device sends indication information to the terminal device when IP verification fails. This feedback allows the terminal to update its secret key or release the RRC connection, preventing the system from continuously processing malicious data and thereby resolving the contradiction between security verification and transmission success rate
Solution Approach 2:
The patent performs preliminary actions by proactively sending indication information when IP verification fails, rather than waiting for data transmission to complete. This preliminary response prevents further transmission of potentially malicious data, maintaining both security and transmission efficiency
2Reliability
If secret key update or RRC connection release is performed when IP verification fails, then communication security is ensured, but device complexity increases due to additional security management procedures
Solution Approach 1:
The patent extracts the security management function into a separate indication information message exchanged between network and terminal. By separating the security verification failure notification from the main data transmission protocol, the complexity is isolated to a specific security management procedure rather than being distributed throughout the entire system
Solution Approach 2:
The indication information acts as an intermediary mechanism between the IP verification function and the secret key management/RRC connection management functions. This intermediary simplifies the interaction by providing a standardized notification protocol that triggers predefined security responses
Data Source
AI summary
Provided are an information transmission method, a network device and a terminal device. The method comprises: a first network device obtains indication information, the indication information being used for indicating integrity protection (IP) check failure of data on a data radio bearer (DRB); the first network device sends the indication information to a second network device. In embodiments of the present application, by means of the indication information, the second network device can update a secret key of the terminal device during the IP check failure of data on the DRB, or the second network device can release RRC connection of the DRB. In this way, the potential safety hazard is eliminated, the communication security is ensured, and therefore, the success rate of data transmission is improved.

