MAC PDU Message Check Codes for Secure Layer Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems lack security protection mechanisms for media access control (MAC) layer messages, leading to privacy leakage and affecting service quality.
Innovation Solution
Implementing message check codes calculated based on payloads within MAC protocol data units (PDUs) to ensure integrity and security at the MAC layer.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security protection mechanisms are provided only at the PDCP layer, then the existing protocol structure is maintained, but the MAC layer messages are vulnerable to privacy leakage and security issues
Solution Approach 1:
The patent divides the security protection function into separate layers: the PDCP layer maintains its existing security mechanisms while the MAC layer introduces a new integrity check code mechanism. This segmentation allows each layer to have specialized security functions without requiring complete protocol restructuring, thereby improving MAC layer security while controlling overall system complexity.
Solution Approach 2:
The patent implements preliminary security action at the MAC layer by calculating integrity check codes before message transmission. The sending device computes the integrity check code based on message content and transmits it with the message, allowing the receiving device to verify integrity before processing, thus preventing security issues early in the communication process.
2Reliability
If integrity check codes are calculated and transmitted for all MAC layer messages, then message integrity is ensured, but transmission overhead increases
Solution Approach 1:
The patent applies partial action by implementing integrity protection selectively rather than universally. The network device configures the terminal to calculate integrity check codes only for specific MAC layer messages that require enhanced security protection, while other messages can transmit without this overhead, thus balancing integrity assurance with transmission efficiency.
Solution Approach 2:
The patent changes the parameter of integrity protection application from binary (all or nothing) to configurable. The network device can dynamically adjust which messages require integrity check codes based on security requirements, message types, and network conditions, allowing optimization between security and overhead by changing the protection scope parameter.
Data Source
AI summary
A communication method includes: receiving, by a first device, a first media access control (MAC) protocol data unit (PDU) from a second device, where the first MAC PDU carries a first message check code, and the first message check code is calculated by the second device based on one or more first payloads of the first MAC PDU.


