5G ProSe Relay UP Traffic Security Adaptation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The protection of user plane (UP) traffic between a remote UE and a UE-to-Network relay in emergency cases within the 5G ProSe UE-to-Network Relay feature is not adequately addressed in existing solutions.
Innovation Solution
A solution where a first terminal device determines that UP traffic should be communicated without confidentiality protection and without integrity protection or with partial integrity protection, and accordingly transmits a message to a second terminal device to facilitate this communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If confidentiality protection and integrity protection are applied to UP traffic between remote UE and UE-to-Network relay, then security is improved, but communication efficiency and reliability in emergency cases deteriorate due to lack of standardized protection mechanisms
Solution Approach 1:
The patent applies parameter changes by dynamically adjusting security protection parameters based on service type. For emergency services, the system modifies the confidentiality protection and integrity protection parameters to be less stringent or disabled, while for non-emergency services, full protection is maintained. This allows the system to optimize communication efficiency for emergency cases without compromising security for regular services.
Solution Approach 2:
The patent implements dynamics by making security protection mechanisms adaptive rather than static. The network device determines whether to apply confidentiality and integrity protection dynamically based on whether the communication is classified as an emergency service. This dynamic approach allows the system to switch between protected and unprotected communication modes according to real-time service requirements.
2Reliability
If full confidentiality and integrity protection are implemented for all UP traffic, then security is improved, but device complexity and processing overhead increase
Solution Approach 1:
The patent applies local quality by differentiating security protection requirements for different types of traffic. Instead of uniformly applying full security protection to all UP traffic, the system applies appropriate protection levels locally based on the service type. Emergency service traffic receives minimal or no protection, while non-emergency traffic receives full protection, optimizing resource usage and reducing unnecessary processing overhead.
3Productivity
If no security protection is applied to UP traffic in emergency cases, then communication efficiency is improved, but security and reliability worsen
Solution Approach 1:
The patent applies partial action by selectively applying security protection only where necessary. For emergency services, the system uses partial or no security protection to maximize communication efficiency, while for non-emergency services, full protection is applied. This partial approach ensures that security measures are not overly applied to situations where they are not needed, thereby maintaining efficiency while providing adequate security.
Data Source
AI summary
Example embodiments of the present disclosure relate to UP traffic handling for emergency case. A first terminal device determines that UP traffic is to be communicated between the first terminal device and a second terminal device without confidentiality protection. The first terminal device determines that the UP traffic is to be communicated between the first terminal device and the second terminal device without integrity protection or with a partial integrity protection. The first terminal device transmits, to the second terminal device, a message indicating that the UP traffic is to be communicated without the confidentiality protection or the integrity protection, or without the confidentiality protection and with the partial integrity protection. In turn, the first terminal device communicates the UP traffic between the first terminal device and the second terminal device without the confidentiality protection or the integrity protection, or without the confidentiality protection and with the partial integrity protection.


