Selective Integrity Protection for Wireless Data Packets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication networks face challenges in efficiently implementing integrity protection for user plane packets due to high computational complexity, which leads to significant processing cycles and potential data throughput degradation, especially with the increasing demand for integrity protection in 5G NR and LTE networks.

Innovation Solution

A method is proposed where data packets are inspected to determine their characteristics, and integrity protection is selectively activated only for those that require it, using a dual flow approach with separate data radio bearers for sensitive and non-sensitive data, thereby reducing the computational burden and focusing protection on critical packets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If integrity protection is applied to all user plane packets, then security against eavesdroppers and data manipulation is improved, but processing complexity and computational cycles increase significantly

Engineering Contradiction:
Improveintegrity protectionVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies integrity protection selectively based on packet characteristics rather than uniformly to all packets. The PDCP layer inspects packets and applies integrity protection only to those requiring it (e.g., control plane messages, sensitive user data), while skipping non-sensitive packets. This local differentiation resolves the contradiction by providing protection where needed without universally increasing processing complexity.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments the user plane data into protected and non-protected flows based on packet inspection. By dividing the data stream and applying integrity protection only to specific segments (packets with certain characteristics), the system achieves selective security that reduces overall processing complexity while maintaining necessary reliability for critical data.

Inventive Principle:
Principle #1Segmentation

2Reliability

If integrity protection is applied to all user plane packets, then security is improved, but data throughput degradation increases

Engineering Contradiction:
Improveintegrity protectionVSAvoiddata throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements partial integrity protection by applying it only to a subset of packets that require security based on their characteristics, rather than to all packets. This partial action approach maintains throughput for non-sensitive traffic while providing necessary protection for sensitive data, thus resolving the contradiction between security and throughput.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

By applying integrity protection locally to specific packets based on inspection results rather than globally to all packets, the system maintains high throughput for non-sensitive traffic while ensuring security for sensitive packets. This localized approach prevents unnecessary throughput degradation.

Inventive Principle:
Principle #3Local quality

3Productivity

If more powerful Application Specific Integrated Circuits are required for integrity protection, then processing capability is improved, but device cost and complexity increase

Engineering Contradiction:
Improveprocessing capabilityVSAvoidASIC complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements dynamic integrity protection where the protection status is determined at runtime based on packet characteristics rather than being statically configured. The PDCP layer inspects each packet and dynamically decides whether to apply integrity protection, allowing the system to adapt processing capability to actual needs without requiring permanently over-provisioned hardware.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of integrity protection application from a fixed state (always on or always off) to a variable state determined by packet characteristics. By changing this parameter dynamically based on inspection results, the system optimizes processing capability usage without requiring more powerful ASICs than necessary.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11606693B2Application of integrity protection in a wireless communication network
Publication Date: 2023.03.14 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US11606693B2 patent drawing
  • US11606693B2 patent drawing
  • US11606693B2 patent drawing

AI summary

A method in a first node of a wireless communications network comprises: inspecting a data packet or message to determine a characteristic of the data packet or message; and selectively activating integrity protection for onward transmission of the data packet or message to a second node of the wireless communications network based on the determined characteristic.