Securing Early Data Transmission in Wireless Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless communication systems face challenges in securely handling Mobile-Terminated (MT) Early Data Transmission (EDT) for Machine-Type Communications (MTC) and Narrowband Internet of Things (NB-IoT), particularly in ensuring the protection of DownLink (DL) data transmitted after the preamble in the Msg2-based option, which requires efficient UE context handling without compromising security.
Innovation Solution
The proposed solution involves a method where the Mobility Management Entity (MME) or source eNB provides ciphered DL data to the target eNB, enabling secure UE context retrieval and transmission of DL data after the preamble, using existing or extended X2-AP and S1-AP procedures, ensuring secure access stratum security and minimizing security risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If DL data is transmitted after preamble in Msg2-based MT-EDT option, then transmission efficiency is improved, but security protection of DL data cannot be ensured
Solution Approach 1:
The source eNB performs ciphering of DL data before transferring it to the target eNB. This preliminary security processing ensures that the data is protected before transmission, resolving the contradiction by establishing security in advance rather than requiring complex real-time security mechanisms during early data transmission
Solution Approach 2:
The source eNB acts as an intermediary that performs the ciphering operation between the data source and the target eNB. This intermediary processing allows the target eNB to simply forward the already-secured data to the UE, maintaining security without compromising transmission efficiency
2Reliability
If UE context is retrieved before DL data transmission, then security can be established, but transmission latency increases
Solution Approach 1:
The source eNB performs ciphering of DL data in advance before the target eNB receives the data. This preliminary action eliminates the need for the target eNB to retrieve UE context before data transmission, as the ciphering is already completed by the source eNB using its local context
Solution Approach 2:
The ciphering function is extracted from the target eNB and performed by the source eNB instead. This extraction allows the target eNB to simply forward data without needing to establish security itself, reducing latency while maintaining security
3Reliability
If ciphering is performed at target eNB, then security is maintained, but processing complexity and time increase
Solution Approach 1:
The ciphering function is extracted from the target eNB and assigned to the source eNB. This extraction simplifies the target eNB's processing requirements while maintaining security, as the source eNB performs the complex ciphering operation using its existing UE context and security keys
Solution Approach 2:
The source eNB performs ciphering using its own stored UE context and security keys without requiring additional authentication or context retrieval from the target eNB. This self-service approach maintains security while reducing overall system complexity and processing time
Data Source
AI summary
There is provided a method in a target network node for performing early data transmission (EDT) when a wireless device has suspended a connection from a source network node. The method comprises: receiving ciphered data from a first network node; sending a message to the wireless device, the message comprising the ciphered data; and in response to the sent message, receiving a message from the wireless device, the message allowing the target network node to retrieve a User Equipment (UE) context of the wireless device from the source network node.


