PDCP Header Encryption for Selective User Plane Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication systems face high processing complexity and overhead due to duplicate security measures, particularly in the user plane, which impact throughput and energy consumption.

Innovation Solution

Implement a method and device for selective user plane security by parsing packet headers to identify and encrypt only those headers without existing security, reducing redundant encryption and optimizing PDCP security processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If duplicate security measures are applied in the user plane, then security reliability is improved, but processing complexity and overhead increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts and removes duplicate security processing from the user plane by identifying packets that already have security protection (via TLS/SSL headers) and excluding them from PDCP security processing. This extraction eliminates redundant encryption operations while maintaining security reliability for packets that require protection.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies local quality by differentiating treatment based on packet characteristics - packets with existing security protection (identified by TLS/SSL headers) are handled differently from packets without security protection. This selective approach applies security processing only where needed, reducing overall processing complexity while maintaining reliability for critical packets.

Inventive Principle:
Principle #3Local quality

2Reliability

If duplicate security measures are applied in the user plane, then security reliability is improved, but throughput is reduced

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidthroughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts packets with existing security protection from the processing pipeline, eliminating redundant encryption operations that would reduce throughput. By removing these duplicate security measures for already-protected packets, the system maintains security reliability for necessary packets while improving overall throughput.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies partial action by providing security processing only to packets that need it (those without existing security protection), rather than applying full security processing to all packets. This partial approach avoids excessive processing on already-protected packets, thereby improving throughput while maintaining adequate security reliability.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If duplicate security measures are applied in the user plane, then security reliability is improved, but energy consumption increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent extracts and removes energy-consuming duplicate security processing operations for packets that already have security protection. By identifying and excluding these packets from PDCP security processing, the system reduces unnecessary cryptographic operations and associated energy consumption while maintaining security reliability for packets that require protection.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies partial security processing only to packets that need protection, avoiding excessive energy consumption on already-protected packets. This selective approach reduces overall energy consumption while maintaining adequate security reliability for critical packets.

Inventive Principle:
Principle #16Partial or excessive action

4Reliability

If security processing is applied to all packets, then security reliability is improved, but CPU utilization increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidCPU utilization
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts packets with existing security protection from CPU processing, eliminating the need for redundant security operations on these packets. This extraction reduces CPU utilization for security processing while maintaining security reliability for packets that require protection.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies local quality by differentiating CPU processing based on packet characteristics - packets with TLS/SSL headers are treated differently from those without. This selective CPU processing reduces overall CPU utilization for security operations while maintaining adequate security reliability for packets that need protection.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250358611A1Method and device for selective user plane security in wireless communication system
Publication Date: 2025.11.20 SAMSUNG ELECTRONICS CO LTD
  • US20250358611A1 patent drawing
  • US20250358611A1 patent drawing
  • US20250358611A1 patent drawing

AI summary

An example security processing method includes receiving data packets at a packet data convergence protocol (PDCP) layer from an upper layer and parsing header information of each of the data packets to determine a length of each of the plurality of headers within the corresponding header information and whether a security header is present or absent in the corresponding data packets. The method further includes identifying corresponding header information of the data packets in which the security header is present based on the determination. The method further includes encrypting, based on the determined header lengths, only each of the plurality of headers of the identified corresponding header information in which the security header is present, and thereafter transmitting the one or more data packets to a lower layer after adding information regarding each of the encrypted headers along with their encryption length into a PDCP header.