Reactive Integrity Protection for Wireless Acknowledgment Containers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current integrity protection mechanisms in wireless communication networks for acknowledging device configuration data are limited, as they precompute message authentication codes (MAC) before transmission, preventing the conveyance of additional information beyond acknowledgment.

Innovation Solution

Generating expected integrity protection data reactively for the transparent container that acknowledges successful reception of device configuration data, allowing it to convey other information securely by checking the integrity of the information fields within the container.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If precomputed MAC is used for integrity protection, then resource usage efficiency is improved, but the ability to securely convey additional information deteriorates

Engineering Contradiction:
Improveresource usage efficiencyVSAvoidability to convey additional information
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent transitions from a static precomputed MAC approach to a dynamic reactive generation approach. The integrity protection data is now generated after the transparent container is constructed, allowing the system to adapt to different information contents while maintaining security. This dynamic timing enables the container to carry variable information beyond simple acknowledgments.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies preliminary action by constructing the complete transparent container with all intended information fields before generating the integrity protection data. This ensures that the MAC covers all information including additional data elements, providing end-to-end integrity protection for the entire message structure.

Inventive Principle:
Principle #10Preliminary action

2Speed

If precomputed MAC is used for integrity protection, then processing speed is improved, but security coverage deteriorates

Engineering Contradiction:
Improveprocessing speedVSAvoidsecurity coverage
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The container structure is prepared in advance with all information fields populated before the final integrity protection generation. This preliminary construction allows the system to maintain processing efficiency while ensuring comprehensive security coverage of all data elements.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The reactive generation of integrity protection data provides feedback-based security verification. The MAC is computed based on the actual container contents including all information fields, creating a feedback loop that ensures the security coverage matches the actual data being transmitted rather than relying on pre-assumed content.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240244435A1Integrity Protection of Acknowledgment Response in a Wireless Communication Network
Publication Date: 2024.07.18 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20240244435A1 patent drawing
  • US20240244435A1 patent drawing
  • US20240244435A1 patent drawing

AI summary

An authentication server (10A) is configured for use in a home network (10H) of a wireless device (12). The authentication server (10A) generates expected integrity protection data for checking an integrity of a set of one or more information fields (22) contained in a transparent container (20) that acknowledges successful reception by the wireless device (12) of device configuration data (14) from the home network (10H). The authentication server (10A) checks, or assists a core network node (16H) in the home network (10H) to check, the integrity of the set of one or more information fields (22) using the expected integrity protection data.