PDCP Version Change via Security Mode Command Integrity Check

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing wireless communication systems, particularly in the transition from 4G to 5G, face challenges in seamlessly changing the Packet Data Convergence Protocol (PDCP) version between LTE and NR, especially during handover scenarios and dual connectivity, which is essential for efficient data transmission and security management.

Innovation Solution

A method and apparatus that allow user equipment (UE) to change PDCP versions by receiving security algorithm configurations from a base station, deriving security keys, and performing integrity protection checks to switch between LTE PDCP and NR PDCP, enabling secure and efficient protocol version changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If PDCP version change is implemented between LTE and NR systems, then adaptability and versatility are improved, but device complexity increases due to the need to support multiple PDCP versions and security algorithms simultaneously

Engineering Contradiction:
ImprovePDCP version change capabilityVSAvoidmulti-PDCP version support complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic PDCP version switching by allowing the UE to change between LTE PDCP and NR PDCP versions based on received security mode command messages. The system dynamically selects which PDCP version to use depending on the security algorithm configuration received from the network, enabling flexible adaptation without permanently maintaining multiple PDCP implementations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The UE is designed with universal PDCP version support, capable of operating with both LTE PDCP and NR PDCP versions through a single multi-functional PDCP layer. This allows the same device to handle multiple protocol versions and security algorithms (EIA0-EIA3, NIA0-NIA3) without requiring separate dedicated PDCP instances for each version.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If integrity protection check is performed using first security key before PDCP version change, then reliability is improved, but loss of time increases due to the additional security verification step

Engineering Contradiction:
Improveintegrity protection verificationVSAvoidsecurity key derivation and verification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs integrity protection verification using the first security key (derived from the current PDCP version's security algorithm) as a preliminary check before executing the PDCP version change. This preliminary verification ensures that the security mode command message is authentic and has not been tampered with, preventing unauthorized or malicious protocol version changes while maintaining system reliability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11564098B2Method and apparatus for activating security and changing PDCP version
Publication Date: 2023.01.24 LG ELECTRONICS INC
  • US11564098B2 patent drawing
  • US11564098B2 patent drawing
  • US11564098B2 patent drawing

AI summary

Provided is a method for changing, by a user equipment (UE), packet data convergence protocol (PDCP) version. The method may include: receiving a security mode command message, which includes a first security algorithm configuration for a PDCP of a first system and a second security algorithm configuration for a PDCP of a second system, from a base station (BS); deriving a first security key for the PDCP of the first system, based on the first security algorithm configuration; when the security mode command message passes an integrity protection check based on the first security key, changing the PDCP version from the PDCP of the first system to the PDCP of the second system; deriving a second security key for the PDCP of the second system, based on the second security algorithm configuration; and transmitting a security mode complete message, based on the second security key, to the BS.