MCData IPCON Session Security With DPPK-Protected IP Tunnels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 3GPP MCS standard specifications lack security for MCData IPCON communications, particularly for IP tunnels between MCData clients, and do not support group communications, with data security often insufficient or absent, and existing methods do not provide end-to-end encryption and media data management.

Innovation Solution

A method for establishing secure MCData IPCON sessions using DPPK keys and encryption mechanisms, enabling end-to-end security for both point-to-point and group communications, with support for GRE in UDP tunnels and media data management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If MCData IPCON service is implemented without security mechanisms, then device complexity and implementation ease are improved, but data security and reliability deteriorate

Engineering Contradiction:
Improveimplementation easeVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by establishing security mechanisms (DPPK key generation, SIP-INVITE message authentication, IP tunnel encryption) before MCData IPCON communications occur. The security framework is pre-configured in the network architecture, with keys generated and distributed beforehand, ensuring that data security is built-in from the outset rather than added as an afterthought.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary security layer between MCData clients and the network. The DPPK (Data Protection Key) acts as a mediator that encrypts data before transmission and decrypts it at the receiving end. The SIP-INVITE message serves as an intermediary authentication mechanism that verifies client identities before establishing secure IP tunnels, thus protecting data security without requiring direct trust between clients.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If end-to-end encryption is implemented for MCData IPCON, then data security is improved, but device complexity and processing overhead increase

Engineering Contradiction:
Improveend-to-end securityVSAvoidsecurity implementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security implementation into distinct modular components: DPPK key generation module, SIP-INVITE authentication module, IP tunnel encryption module, and data encryption/decryption modules. Each component performs a specific security function independently, making the overall complex security system manageable through modular design. This segmentation allows each module to be optimized and maintained separately while working together to provide end-to-end security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses intermediaries to reduce the complexity burden on end devices. The network infrastructure acts as an intermediary that handles key distribution, authentication, and tunnel management. The DPPK key serves as an intermediary that simplifies the encryption process by providing a pre-shared secret that both clients can use without needing to perform complex key exchange protocols themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If security mechanisms are added to MCData IPCON, then data security is improved, but processing time and session establishment duration increase

Engineering Contradiction:
Improvedata protectionVSAvoidsession establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-generating DPPK keys and pre-establishing security associations before actual data transmission begins. The SIP-INVITE authentication and IP tunnel setup are completed in advance during the session initiation phase, so that once the secure channel is established, data can be transmitted immediately without repeated authentication overhead. This preliminary security setup minimizes the time penalty during ongoing communications.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements optimized security verification that skips redundant authentication steps. Once the SIP-INVITE message is authenticated and the IP tunnel is established, subsequent data transmissions within the same session bypass repeated authentication procedures. The system rushes through the essential security checks during setup and then maintains the secure state efficiently, reducing overall time loss.

Inventive Principle:
Principle #21Skipping (Rushing through)

4Adaptability or versatility

If group communications are supported in addition to point-to-point, then service versatility is improved, but device complexity and management overhead increase

Engineering Contradiction:
Improvecommunication mode supportVSAvoidsession management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal security framework that serves both point-to-point and group communication modes through the same mechanism. The DPPK key structure and SIP-INVITE authentication process remain consistent across different communication types. For group communications, the same security principles apply but are extended to multiple participants, allowing the system to handle diverse communication scenarios with a single unified approach rather than requiring separate security implementations for each mode.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments group communication security into manageable components: individual client authentication via SIP-INVITE, group IP tunnel establishment, and collective data protection using shared DPPK keys. Each group session is treated as a separate segment with its own security context, allowing independent management of different groups while maintaining consistent security policies. This segmentation enables versatile communication mode support without overwhelming complexity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12549366B2IPCON MCData session establishment method
Publication Date: 2026.02.10 AIRBUS DS SLC
  • US12549366B2 patent drawing
  • US12549366B2 patent drawing

AI summary

A method for establishing an IPCON Mission Critical Data Internet Protocol Connectivity MCData session in a communications network according to the 3GPP MCS 3rd Generation Partnership Program Mission Critical System standard. The network includes an emitting MCData entity, a destination MCData entity and an MCData transport service connected to the emitting and destination MCData entities. The method includes obtaining, from the emitting MCData entity, a DPPK MCData Payload Protection Key and a DPPK-ID MCData Payload Protection Key Identifier, transmitting a SIP-INVITE message comprising the DPPK key and the DPPK-IK key identifier, from the emitting MCData entity to the destination MCData entity via the MCData transport service, authenticating the message, by the destination MCData entity, and determining the DPPK key and the DPPK-ID key identifier, by the destination MCData entity, and establishing an IP tunnel between the emitting MCData entity and the destination MCData entity.