Null-Encryption Security Association for Wireless Packet Transport
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current secure IP tunnels in wireless communication systems are inefficient for certain types of traffic, such as SIP signaling and VoIP media packets, due to the processing load incurred by IPsec encryption, which can be avoided by enabling null-encryption for these packets.
Innovation Solution
Establishing two IPsec security associations in each direction between a mobile station and a secure gateway, one for encryption and one for null-encryption, with traffic selectors configured to apply null-encryption to specific packets like SIP signaling and VoIP media packets, thereby reducing processing load and conserving resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IPsec encryption is applied to all packets between mobile station and secure gateway, then security is improved, but processing load and device complexity increase
Solution Approach 1:
The patent applies different encryption treatments to different packet types based on their specific security requirements. SIP signaling packets receive null-encryption (no encryption) while VoIP media packets receive full IPsec encryption. This local differentiation allows the system to maintain security where needed while reducing processing load where full encryption is unnecessary, directly resolving the contradiction between security and processing complexity.
Solution Approach 2:
The patent segments the packet flow into different categories (SIP signaling packets and VoIP media packets) and applies different security associations (null-encryption SA and full encryption SA) to each segment. This segmentation enables selective encryption that reduces overall processing load while maintaining security for critical traffic types.
2Reliability
If full IPsec encryption is used for all traffic types, then security is improved, but productivity decreases due to processing overhead
Solution Approach 1:
The patent applies different encryption treatments to different packet types based on their specific security requirements. SIP signaling packets receive null-encryption (no encryption) while VoIP media packets receive full IPsec encryption. This local differentiation allows the system to maintain security where needed while reducing processing load where full encryption is unnecessary, directly resolving the contradiction between security and processing complexity.
Solution Approach 2:
The patent applies partial encryption only to the portion of traffic that requires it (VoIP media packets), while leaving other traffic (SIP signaling packets) unencrypted through null-encryption. This partial action approach avoids the excessive processing overhead of applying full encryption to all traffic types while maintaining security where necessary.
3Productivity
If null-encryption is applied to SIP signaling packets, then processing load is reduced, but security coverage is limited
Solution Approach 1:
The patent applies different encryption treatments to different packet types based on their specific security requirements. SIP signaling packets receive null-encryption (no encryption) while VoIP media packets receive full IPsec encryption. This local differentiation allows the system to maintain security where needed while reducing processing load where full encryption is unnecessary, directly resolving the contradiction between security and processing complexity.
Solution Approach 2:
The patent segments the packet flow into different categories (SIP signaling packets and VoIP media packets) and applies different security associations (null-encryption SA and full encryption SA) to each segment. This segmentation enables selective encryption that reduces overall processing load while maintaining security for critical traffic types.
Data Source
AI summary
Disclosed is a method for efficient transport of packets between a mobile station and a secure gateway over a wireless local area network for accessing home services. In the method, a first encryption security association is established for transporting first-type packets from the secure gateway to the mobile station, and a second encryption security association is established for transporting first-type packets from the mobile station to the secure gateway. Next, a first null-encryption security association is established for transporting second-type packets from the secure gateway to the mobile station, and a second null-encryption security association is established for transporting second-type packets from the mobile station to the secure gateway. Second-type packets are selected for transport using the second null-encryption security association based on a traffic selector. Also, second-type packets may be selected for transport using the first null-encryption security association based on a traffic selector. The traffic selector may be preconfigured.


