Integrity Protection Failure Handling in LTE-NR Dual Connectivity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the transition to 5G mobile communication, the integration of LTE and NR networks faces challenges due to limited spectrum availability below 6 GHz, leading to security risks from malicious data alterations during integrity protection verification failures in data radio bearers, which can compromise communication security and data transmission success rates.

Innovation Solution

A method is introduced where network devices obtain and send indication information when integrity protection verification fails, allowing for updating the secret key or releasing the RRC connection of a data radio bearer, thereby ensuring communication security and improving data transmission success rates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If integrity protection verification is implemented on data radio bearer in NR, then communication security is improved, but data transmission success rate deteriorates due to malicious data alterations being discarded

Engineering Contradiction:
Improvecommunication securityVSAvoiddata transmission success rate
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements a feedback mechanism where the network device sends indication information to the terminal device when IP verification fails. This feedback allows the terminal to update its secret key or release the RRC connection, preventing the system from continuously processing malicious data and thereby resolving the contradiction between security verification and transmission success rate

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary actions by proactively sending indication information when IP verification fails, rather than waiting for data transmission to complete. This preliminary response prevents further transmission of potentially malicious data, maintaining both security and transmission efficiency

Inventive Principle:
Principle #10Preliminary action

2Reliability

If secret key update or RRC connection release is performed when IP verification fails, then communication security is ensured, but device complexity increases due to additional security management procedures

Engineering Contradiction:
Improvecommunication securityVSAvoidsecurity management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security management function into a separate indication information message exchanged between network and terminal. By separating the security verification failure notification from the main data transmission protocol, the complexity is isolated to a specific security management procedure rather than being distributed throughout the entire system

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The indication information acts as an intermediary mechanism between the IP verification function and the secret key management/RRC connection management functions. This intermediary simplifies the interaction by providing a standardized notification protocol that triggers predefined security responses

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11553344B2Information transmission method, network device and terminal device
Publication Date: 2023.01.10 GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
  • US11553344B2 patent drawing
  • US11553344B2 patent drawing

AI summary

Provided are an information transmission method, a network device and a terminal device. The method comprises: a first network device obtains indication information, the indication information being used for indicating integrity protection (IP) check failure of data on a data radio bearer (DRB); the first network device sends the indication information to a second network device. In embodiments of the present application, by means of the indication information, the second network device can update a secret key of the terminal device during the IP check failure of data on the DRB, or the second network device can release RRC connection of the DRB. In this way, the potential safety hazard is eliminated, the communication security is ensured, and therefore, the success rate of data transmission is improved.