Selective PDCP Header Encryption for Wireless User Plane Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication systems face high processing complexity and overhead due to duplicate security measures in the user plane, leading to increased CPU utilization and power consumption, particularly in 5G networks, as data is often encrypted multiple times, which is inefficient and costly.

Innovation Solution

Implement a method and device for selective user plane security by parsing packet headers to identify and encrypt only those headers lacking security, avoiding redundant encryption of already encrypted data, and optimizing PDCP header structures for enhanced data plane processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If duplicate security measures are applied in the user plane, then data security is enhanced, but processing complexity and CPU utilization increase

Engineering Contradiction:
Improvedata securityVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies partial security measures by selectively encrypting only specific portions of data (e.g., header fields) rather than applying full encryption to entire data streams. This partial action approach reduces processing complexity while maintaining security for critical data elements, resolving the contradiction between enhanced security and reduced processing burden.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent implements local quality by applying different security treatments to different parts of the data packet. Critical header fields receive encryption while other fields may be transmitted in plaintext, allowing security to be concentrated where most needed without uniformly increasing processing complexity across the entire data stream.

Inventive Principle:
Principle #3Local quality

2Reliability

If duplicate encryption is applied to already encrypted data, then security coverage is improved, but CPU cycles and energy consumption increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidCPU cycles
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent performs preliminary identification of already encrypted data through header parsing and encryption status detection before applying security measures. This preliminary action prevents redundant encryption operations on data that is already protected, reducing CPU cycles while ensuring security coverage is applied only where needed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system performs self-service by automatically detecting the encryption status of incoming data and making intelligent decisions about whether additional encryption is necessary. This self-determination mechanism eliminates unnecessary CPU cycles spent on re-encrypting already protected data while maintaining comprehensive security coverage.

Inventive Principle:
Principle #25Self-service

3Reliability

If security headers are parsed and processed for each packet, then security verification is improved, but processing overhead increases

Engineering Contradiction:
Improvesecurity verificationVSAvoidsystem throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial processing by examining only specific security-critical header fields rather than parsing every possible header component. This selective verification approach maintains essential security checks while reducing processing overhead and improving overall system throughput.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent replaces exhaustive mechanical parsing of all packet headers with a more efficient verification mechanism that checks encryption status through targeted field examination. This substitution reduces processing overhead while maintaining security verification reliability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12418792B2Method and device for selective user plane security in wireless communication system
Publication Date: 2025.09.16 SAMSUNG ELECTRONICS CO LTD
  • US12418792B2 patent drawing
  • US12418792B2 patent drawing
  • US12418792B2 patent drawing

AI summary

An example security processing method includes receiving data packets at a packet data convergence protocol (PDCP) layer from an upper layer and parsing header information of each of the data packets to determine a length of each of the plurality of headers within the corresponding header information and whether a security header is present or absent in the corresponding data packets. The method further includes identifying corresponding header information of the data packets in which the security header is present based on the determination. The method further includes encrypting, based on the determined header lengths, only each of the plurality of headers of the identified corresponding header information in which the security header is present, and thereafter transmitting the one or more data packets to a lower layer after adding information regarding each of the encrypted headers along with their encryption length into a PDCP header.