PDCP Header Encryption for Selective User Plane Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication systems face high processing complexity and overhead due to duplicate security measures, particularly in the user plane, which impact throughput and energy consumption.
Innovation Solution
Implement a method and device for selective user plane security by parsing packet headers to identify and encrypt only those headers without existing security, reducing redundant encryption and optimizing PDCP security processing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If duplicate security measures are applied in the user plane, then security reliability is improved, but processing complexity and overhead increase
Solution Approach 1:
The patent extracts and removes duplicate security processing from the user plane by identifying packets that already have security protection (via TLS/SSL headers) and excluding them from PDCP security processing. This extraction eliminates redundant encryption operations while maintaining security reliability for packets that require protection.
Solution Approach 2:
The patent applies local quality by differentiating treatment based on packet characteristics - packets with existing security protection (identified by TLS/SSL headers) are handled differently from packets without security protection. This selective approach applies security processing only where needed, reducing overall processing complexity while maintaining reliability for critical packets.
2Reliability
If duplicate security measures are applied in the user plane, then security reliability is improved, but throughput is reduced
Solution Approach 1:
The patent extracts packets with existing security protection from the processing pipeline, eliminating redundant encryption operations that would reduce throughput. By removing these duplicate security measures for already-protected packets, the system maintains security reliability for necessary packets while improving overall throughput.
Solution Approach 2:
The patent applies partial action by providing security processing only to packets that need it (those without existing security protection), rather than applying full security processing to all packets. This partial approach avoids excessive processing on already-protected packets, thereby improving throughput while maintaining adequate security reliability.
3Reliability
If duplicate security measures are applied in the user plane, then security reliability is improved, but energy consumption increases
Solution Approach 1:
The patent extracts and removes energy-consuming duplicate security processing operations for packets that already have security protection. By identifying and excluding these packets from PDCP security processing, the system reduces unnecessary cryptographic operations and associated energy consumption while maintaining security reliability for packets that require protection.
Solution Approach 2:
The patent applies partial security processing only to packets that need protection, avoiding excessive energy consumption on already-protected packets. This selective approach reduces overall energy consumption while maintaining adequate security reliability for critical packets.
4Reliability
If security processing is applied to all packets, then security reliability is improved, but CPU utilization increases
Solution Approach 1:
The patent extracts packets with existing security protection from CPU processing, eliminating the need for redundant security operations on these packets. This extraction reduces CPU utilization for security processing while maintaining security reliability for packets that require protection.
Solution Approach 2:
The patent applies local quality by differentiating CPU processing based on packet characteristics - packets with TLS/SSL headers are treated differently from those without. This selective CPU processing reduces overall CPU utilization for security operations while maintaining adequate security reliability for packets that need protection.
Data Source
AI summary
An example security processing method includes receiving data packets at a packet data convergence protocol (PDCP) layer from an upper layer and parsing header information of each of the data packets to determine a length of each of the plurality of headers within the corresponding header information and whether a security header is present or absent in the corresponding data packets. The method further includes identifying corresponding header information of the data packets in which the security header is present based on the determination. The method further includes encrypting, based on the determined header lengths, only each of the plurality of headers of the identified corresponding header information in which the security header is present, and thereafter transmitting the one or more data packets to a lower layer after adding information regarding each of the encrypted headers along with their encryption length into a PDCP header.


