Securing Early Data Transmission in Wireless Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication systems face challenges in securely handling Mobile-Terminated (MT) Early Data Transmission (EDT) for Machine-Type Communications (MTC) and Narrowband Internet of Things (NB-IoT), particularly in ensuring the protection of DownLink (DL) data transmitted after the preamble in the Msg2-based option, which requires efficient UE context handling without compromising security.

Innovation Solution

The proposed solution involves a method where the Mobility Management Entity (MME) or source eNB provides ciphered DL data to the target eNB, enabling secure UE context retrieval and transmission of DL data after the preamble, using existing or extended X2-AP and S1-AP procedures, ensuring secure access stratum security and minimizing security risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If DL data is transmitted after preamble in Msg2-based MT-EDT option, then transmission efficiency is improved, but security protection of DL data cannot be ensured

Engineering Contradiction:
Improvetransmission efficiencyVSAvoidsecurity protection
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The source eNB performs ciphering of DL data before transferring it to the target eNB. This preliminary security processing ensures that the data is protected before transmission, resolving the contradiction by establishing security in advance rather than requiring complex real-time security mechanisms during early data transmission

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The source eNB acts as an intermediary that performs the ciphering operation between the data source and the target eNB. This intermediary processing allows the target eNB to simply forward the already-secured data to the UE, maintaining security without compromising transmission efficiency

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If UE context is retrieved before DL data transmission, then security can be established, but transmission latency increases

Engineering Contradiction:
Improvesecurity establishmentVSAvoidtransmission latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The source eNB performs ciphering of DL data in advance before the target eNB receives the data. This preliminary action eliminates the need for the target eNB to retrieve UE context before data transmission, as the ciphering is already completed by the source eNB using its local context

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The ciphering function is extracted from the target eNB and performed by the source eNB instead. This extraction allows the target eNB to simply forward data without needing to establish security itself, reducing latency while maintaining security

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If ciphering is performed at target eNB, then security is maintained, but processing complexity and time increase

Engineering Contradiction:
Improvesecurity maintenanceVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The ciphering function is extracted from the target eNB and assigned to the source eNB. This extraction simplifies the target eNB's processing requirements while maintaining security, as the source eNB performs the complex ciphering operation using its existing UE context and security keys

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The source eNB performs ciphering using its own stored UE context and security keys without requiring additional authentication or context retrieval from the target eNB. This self-service approach maintains security while reducing overall system complexity and processing time

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20220159466A1Methods for handling security of early mobile-terminated data transmissions
Publication Date: 2022.05.19 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20220159466A1 patent drawing
  • US20220159466A1 patent drawing
  • US20220159466A1 patent drawing

AI summary

There is provided a method in a target network node for performing early data transmission (EDT) when a wireless device has suspended a connection from a source network node. The method comprises: receiving ciphered data from a first network node; sending a message to the wireless device, the message comprising the ciphered data; and in response to the sent message, receiving a message from the wireless device, the message allowing the target network node to retrieve a User Equipment (UE) context of the wireless device from the source network node.