MAC PDU Fixed Part Ciphering for Wireless Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security mechanisms in wireless communication systems, particularly in the PDCP layer, leave lower layers and control PDUs unprotected, making them vulnerable to attacks as more functions are implemented on the MAC layer, and straightforward ciphering solutions at the MAC or physical layers face challenges with increased overhead and real-time processing requirements.
Innovation Solution
Implementing a security mechanism that ciphers a fixed part of the MAC PDUs at the MAC layer, known as the Protected Zone, which includes MAC control elements and headers, while maintaining ciphering at the PDCP layer, to provide protection without increasing real-time processing demands.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If ciphering is implemented at the MAC layer for all data, then security is improved, but real-time processing requirements become too stringent
Solution Approach 1:
The MAC PDU is divided into two parts: a fixed part (headers and MAC control elements) that is ciphered, and a variable part (MAC SDUs) that remains unciphered. This segmentation allows critical control information to be protected while avoiding the real-time processing burden of ciphering all data
Solution Approach 2:
Different parts of the MAC PDU receive different security treatment. The fixed part containing control elements and headers is ciphered to ensure security, while the variable part containing user data is left unciphered to maintain processing efficiency
2Productivity
If ciphering is moved to the PDCP layer, then real-time processing requirements are reduced, but lower layers and control PDUs become unprotected
Solution Approach 1:
The solution segments the protection scope: PDCP layer ciphering protects user data, while MAC layer ciphering protects control elements and headers. This dual-layer segmentation ensures both data and control information are secured without compromising processing capability
Solution Approach 2:
The MAC layer acts as an intermediary between the physical layer and PDCP layer, providing an additional security layer specifically for control elements and headers that neither pure MAC nor pure PDCP ciphering can provide alone
3Adaptability or versatility
If MAC layer functions are expanded, then system functionality is improved, but vulnerability to attacks increases
Solution Approach 1:
The patent applies preliminary anti-action by ciphering the fixed part of MAC PDUs before transmission. This pre-encryption of control elements and headers prevents attackers from exploiting expanded MAC layer functions, countering potential threats before they can be executed
Data Source
AI summary
Methods and apparatus are disclosed for security of a wireless communication between a communication device and a counterpart communication device. A method performed at the communication device comprises, ciphering a fixed part of a medium access control (MAC) protocol data unit (PDU) at MAC layer for the wireless communication. The fixed part of the MAC PDU comprises at least one of the following fields: at least one MAC control element, or at least one header of radio protocol in the MAC PDU.


