5G NR Lower-Layer Security for L1/L2 Message Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing 5G NR security protocols inadequately protect lower layers of the radio protocol stack, particularly L1/L2 control and header messages, leading to vulnerabilities such as false base station attacks and system information broadcast issues, with inefficiencies in activation/deactivation mechanisms and digital signature overhead.

Innovation Solution

Relocate security protection functions to lower layers of the radio protocol stack, derive and select input parameters for security algorithms, and implement security functions at L2/L1 layers to protect L2/L1 messages, using bearer IDs, logical channel IDs, and sequence numbers to enhance security and reduce overhead.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security protection functions are relocated to lower layers of the radio protocol stack, then air interface security is enhanced, but device complexity increases

Engineering Contradiction:
Improveair interface securityVSAvoidsecurity function implementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments security protection functions by protocol layer, implementing distinct security mechanisms for L1 control messages, L2 control messages, and L3 messages. Each layer receives tailored security processing with appropriate input parameters (physical layer identity for L1, logical channel identity for L2, bearer identity for L3), dividing the complex security system into manageable modular components that can be independently implemented and maintained.

Inventive Principle:
Principle #1Segmentation

2Productivity

If digital signature overhead is reduced in system information broadcasting, then transmission efficiency improves, but security protection capability deteriorates

Engineering Contradiction:
Improvesystem information transmission efficiencyVSAvoidsystem information security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies partial action by implementing integrity protection selectively - not all system information requires full digital signature protection. Critical system information blocks receive integrity protection while less sensitive information can use lighter protection mechanisms, reducing overall overhead while maintaining security for essential broadcast data.

Inventive Principle:
Principle #16Partial or excessive action

3Speed

If security functions are implemented at L2/L1 layers, then activation and deactivation speed improves, but processing complexity increases

Engineering Contradiction:
Improveactivation and deactivation speedVSAvoidsecurity processing complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-configuring security parameters and contexts at lower layers before actual security operations are needed. Security algorithms, keys, and processing routines are prepared in advance at L1/L2, enabling rapid activation and deactivation without complex runtime configuration, thus improving speed while managing complexity through upfront preparation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250280040A1NR security enhancements
Publication Date: 2025.09.04 INTERDIGITAL PATENT HOLDINGS INC
  • US20250280040A1 patent drawing
  • US20250280040A1 patent drawing
  • US20250280040A1 patent drawing

AI summary

Radio security enhancements may include methods for derivation and selection of input parameters for security functions in radio protocol stack. Systems may relocate security protection functions to lower layers of the radio protocol stack.