Selective Integrity Protection for Wireless Data Packets
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless communication networks face challenges in efficiently implementing integrity protection for user plane packets due to high computational complexity, which leads to significant processing cycles and potential data throughput degradation, especially with the increasing demand for integrity protection in 5G NR and LTE networks.
Innovation Solution
A method is proposed where data packets are inspected to determine their characteristics, and integrity protection is selectively activated only for those that require it, using a dual flow approach with separate data radio bearers for sensitive and non-sensitive data, thereby reducing the computational burden and focusing protection on critical packets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If integrity protection is applied to all user plane packets, then security against eavesdroppers and data manipulation is improved, but processing complexity and computational cycles increase significantly
Solution Approach 1:
The patent applies integrity protection selectively based on packet characteristics rather than uniformly to all packets. The PDCP layer inspects packets and applies integrity protection only to those requiring it (e.g., control plane messages, sensitive user data), while skipping non-sensitive packets. This local differentiation resolves the contradiction by providing protection where needed without universally increasing processing complexity.
Solution Approach 2:
The patent segments the user plane data into protected and non-protected flows based on packet inspection. By dividing the data stream and applying integrity protection only to specific segments (packets with certain characteristics), the system achieves selective security that reduces overall processing complexity while maintaining necessary reliability for critical data.
2Reliability
If integrity protection is applied to all user plane packets, then security is improved, but data throughput degradation increases
Solution Approach 1:
The patent implements partial integrity protection by applying it only to a subset of packets that require security based on their characteristics, rather than to all packets. This partial action approach maintains throughput for non-sensitive traffic while providing necessary protection for sensitive data, thus resolving the contradiction between security and throughput.
Solution Approach 2:
By applying integrity protection locally to specific packets based on inspection results rather than globally to all packets, the system maintains high throughput for non-sensitive traffic while ensuring security for sensitive packets. This localized approach prevents unnecessary throughput degradation.
3Productivity
If more powerful Application Specific Integrated Circuits are required for integrity protection, then processing capability is improved, but device cost and complexity increase
Solution Approach 1:
The patent implements dynamic integrity protection where the protection status is determined at runtime based on packet characteristics rather than being statically configured. The PDCP layer inspects each packet and dynamically decides whether to apply integrity protection, allowing the system to adapt processing capability to actual needs without requiring permanently over-provisioned hardware.
Solution Approach 2:
The patent changes the parameter of integrity protection application from a fixed state (always on or always off) to a variable state determined by packet characteristics. By changing this parameter dynamically based on inspection results, the system optimizes processing capability usage without requiring more powerful ASICs than necessary.
Data Source
AI summary
A method in a first node of a wireless communications network comprises: inspecting a data packet or message to determine a characteristic of the data packet or message; and selectively activating integrity protection for onward transmission of the data packet or message to a second node of the wireless communications network based on the determined characteristic.


