Securing PDCP Control PDUs via Dedicated Counters

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless communication systems often lack secure protocols for PDCP control PDUs, making them vulnerable to attacks and disruptions, particularly since control information generated by or related to the PDCP layer is not typically secured.

Innovation Solution

A method and apparatus for securing PDCP control PDUs by determining a security configuration based on the content of the PDU, using a dedicated counter for processing security protocols, and sharing security parameters across communication links to apply appropriate security protocols such as integrity protection and ciphering.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security protocols are applied to PDCP control PDUs, then security protection is improved, but processing complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments security processing by introducing a dedicated counter for PDCP control PDUs separate from the data PDU counter. This allows control PDUs to be processed with appropriate security measures without interfering with data PDU processing, thereby managing complexity while maintaining security protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security configurations based on the type of PDU. Control PDUs receive security protection configured specifically for control information, while data PDUs follow separate security handling. This localized approach ensures appropriate security without uniformly increasing complexity across all processing.

Inventive Principle:
Principle #3Local quality

2Productivity

If separate counters are used for control and data PDUs, then processing efficiency is improved, but device complexity increases

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidcounter management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements separate counters for control PDUs and data PDUs, allowing independent tracking and processing. This segmentation enables optimized processing efficiency for each PDU type while the structured separation actually reduces overall system complexity by preventing interference between control and data processing.

Inventive Principle:
Principle #1Segmentation

3Loss of time

If security configurations are shared across communication links, then processing time is reduced, but security configuration management complexity increases

Engineering Contradiction:
Improveprocessing timeVSAvoidconfiguration management complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent implements a universal security configuration framework that can be shared across multiple communication links. The same security management mechanisms serve both control PDUs and data PDUs, as well as multiple links, thereby reducing processing time through reuse while the standardized approach actually simplifies management complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10757754B2Techniques for securing PDCP control PDU
Publication Date: 2020.08.25 QUALCOMM INC
  • US10757754B2 patent drawing
  • US10757754B2 patent drawing
  • US10757754B2 patent drawing

AI summary

Techniques are described herein to secure a packet data convergence protocol (PDCP) control protocol data unit (PDU). A base station may determine a security configuration for a PDCP control PDU based on various factors including the content of the PDCP control PDU. For example, the security configuration of the PDCP control PDU may be applied because the PDCP control PDU includes a retransmission request. A counter dedicated to PDCP control PDUs may be initialized. The security protocols may be based on the dedicated counter. Some types of security parameters may be shared in some contexts such as in handover procedures or dual connectivity procedures. For example, security configurations associated with a second communication link may be based on security configurations associated with a first communication link. PDCP control PDUs may be secured based on the security configurations, the security parameters, protection keys, or combinations thereof.