Relay Node Integrity Protection for LTE Signaling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current LTE security mechanisms do not provide adequate integrity protection for S1-AP and X2-AP messages on the Un interface, leading to reduced bandwidth and user experience, especially when integrity protection is activated for all data bearers, and existing solutions like IPsec degrade resource efficiency in radio interfaces.

Innovation Solution

Implementing a method where the relay node (RN) receives integrity protection information from the base station and applies it to specific bearers carrying S1-AP and X2-AP messages, allowing for selective integrity protection without increasing system load, by activating integrity protection per bearer rather than for all bearers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If integrity protection is activated for all data bearers on the Un interface, then security reliability is improved, but radio interface efficiency deteriorates due to increased system load

Engineering Contradiction:
Improveintegrity protectionVSAvoidradio interface efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies integrity protection selectively to specific bearers (S1-AP and X2-AP bearers) rather than all data bearers. The base station determines which bearers require integrity protection based on their traffic type, and only activates integrity protection for those specific bearers. This local application of integrity protection maintains security for critical signaling while avoiding the performance degradation that would occur if integrity protection were applied universally to all bearers.

Inventive Principle:
Principle #3Local quality

2Productivity

If integrity protection is not provided for S1-AP and X2-AP messages, then radio interface efficiency is maintained, but security reliability deteriorates

Engineering Contradiction:
Improveradio interface efficiencyVSAvoidintegrity protection
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements differentiated security treatment where S1-AP and X2-AP bearers receive integrity protection while other data bearers do not. The base station identifies the bearer type and applies integrity protection only to signaling bearers (S1-AP, X2-AP) that require security. This resolves the contradiction by providing security where needed without compromising overall radio interface efficiency.

Inventive Principle:
Principle #3Local quality

3Reliability

If existing solutions like IPsec are used to provide integrity protection, then security reliability is improved, but device complexity increases and resource efficiency deteriorates

Engineering Contradiction:
Improveintegrity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the integrity protection function from complex external security protocols like IPsec and implements it natively within the LTE security framework at the PDCP layer. By using the existing integrity protection algorithms and mechanisms already defined in LTE (such as those used for uplink data integrity), the system achieves the same security goals without introducing the complexity and resource overhead associated with IPsec implementations.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent leverages the existing universal integrity protection mechanisms already built into the LTE system for uplink data transmission. These same mechanisms are applied to downlink S1-AP and X2-AP bearers, eliminating the need for separate or additional security protocols. This multi-functional use of existing security infrastructure maintains reliability while avoiding increased device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2523487B1Method, apparatus and system for realizing integrity protection
Publication Date: 2017.09.06 CHINA ACAD OF TELECOMM TECH
  • EP2523487B1 patent drawingFigure 1~2
  • EP2523487B1 patent drawingFigure 3~4
  • EP2523487B1 patent drawingFigure 5~6

AI summary

Provided in the present invention are a method, an apparatus and a system for realizing integrity protection. The method includes the following steps: a relay node (RN) receives a message, from a base station, carrying integrity protection information; the RN provides integrity protection for the transmitted data according to the integrity protection information. The embodiments of the present invention can provide integrity protection for the data that requires the integrity protection, especially for S1-AP messages and X2-AP messages.