PDCP Security Failure Detection in LTE Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing LTE system lacks a function to detect Hyper Frame Number (HFN) de-synchronization, leading to security failures and continuous discarding of received data packets, as current methods cannot recover from this issue once it occurs.
Innovation Solution
A method is introduced to detect security failures by counting error packets, comparing them to a reference value, and performing a recovery process, including notifying the RRC layer to re-establish or reset the Radio Bearer and security configuration, using a PDCP RESET process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the existing LTE system operates without HFN de-synchronization detection function, then the system structure remains simple, but security failures occur and data packets are continuously discarded
Solution Approach 1:
The patent implements preliminary detection of HFN de-synchronization by monitoring packet errors before complete security failure occurs. The detection mechanism proactively identifies synchronization issues by counting error packets and comparing against thresholds, allowing the system to reset security configurations before catastrophic failure, thus improving reliability without requiring complex post-failure recovery mechanisms
Solution Approach 2:
The patent establishes a feedback loop where packet error rates are continuously monitored and fed back to the security management function. When the error packet count reaches a predetermined threshold, the system triggers a security reset procedure. This feedback mechanism enables automatic adaptation to security state changes, improving reliability through continuous monitoring while maintaining relatively simple implementation through threshold-based decision logic
2Loss of information
If security failure detection is implemented, then data loss is prevented, but the processing complexity increases
Solution Approach 1:
The patent applies partial action by implementing detection only for error packets that indicate potential HFN de-synchronization, rather than analyzing every packet in detail. The system counts error packets and compares against a threshold, triggering security reset only when necessary. This selective monitoring approach prevents data loss while avoiding the complexity of comprehensive packet analysis for every transmitted frame
Solution Approach 2:
The patent changes the monitoring parameter from detailed packet content analysis to simple error packet counting. By focusing on the quantity of error packets rather than their specific content, the system achieves effective security failure detection with minimal processing complexity. The predetermined threshold parameter provides a simple criterion for triggering security reset, balancing detection effectiveness with processing simplicity
3Loss of time
If continuous packet monitoring is performed, then security failures are detected timely, but radio resources are consumed
Solution Approach 1:
The patent implements periodic monitoring by counting error packets over a defined period and comparing against a threshold, rather than continuously analyzing every packet in real-time. This periodic evaluation approach enables timely detection of security failures while reducing radio resource consumption by processing monitoring data at intervals rather than continuously, achieving a balance between detection speed and resource efficiency
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method and apparatus for detecting a security error at a PDCP layer of an LTE (Long Term Evolution) system, a mobile communication system, are disclosed. Conditions for determining a security failure are defined. A receiving side PDCP determines whether HFN de-synchronization, namely, a security failure, has occurred by using particular conditions (namely, conditions for determining the security failure). If it is determined that the security failure has occurred, the receiving side PDCP informs an RRC to re-establish an RB or perform a PDCP RESET process to reset security configuration of a transmitting side and the receiving side.