Selective PDCP Header Encryption for Wireless User Plane Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication systems face high processing complexity and overhead due to duplicate security measures in the user plane, leading to increased CPU utilization and power consumption, particularly in 5G networks, as data is often encrypted multiple times, which is inefficient and costly.
Innovation Solution
Implement a method and device for selective user plane security by parsing packet headers to identify and encrypt only those headers lacking security, avoiding redundant encryption of already encrypted data, and optimizing PDCP header structures for enhanced data plane processing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If duplicate security measures are applied in the user plane, then data security is enhanced, but processing complexity and CPU utilization increase
Solution Approach 1:
The patent applies partial security measures by selectively encrypting only specific portions of data (e.g., header fields) rather than applying full encryption to entire data streams. This partial action approach reduces processing complexity while maintaining security for critical data elements, resolving the contradiction between enhanced security and reduced processing burden.
Solution Approach 2:
The patent implements local quality by applying different security treatments to different parts of the data packet. Critical header fields receive encryption while other fields may be transmitted in plaintext, allowing security to be concentrated where most needed without uniformly increasing processing complexity across the entire data stream.
2Reliability
If duplicate encryption is applied to already encrypted data, then security coverage is improved, but CPU cycles and energy consumption increase
Solution Approach 1:
The patent performs preliminary identification of already encrypted data through header parsing and encryption status detection before applying security measures. This preliminary action prevents redundant encryption operations on data that is already protected, reducing CPU cycles while ensuring security coverage is applied only where needed.
Solution Approach 2:
The system performs self-service by automatically detecting the encryption status of incoming data and making intelligent decisions about whether additional encryption is necessary. This self-determination mechanism eliminates unnecessary CPU cycles spent on re-encrypting already protected data while maintaining comprehensive security coverage.
3Reliability
If security headers are parsed and processed for each packet, then security verification is improved, but processing overhead increases
Solution Approach 1:
The patent applies partial processing by examining only specific security-critical header fields rather than parsing every possible header component. This selective verification approach maintains essential security checks while reducing processing overhead and improving overall system throughput.
Solution Approach 2:
The patent replaces exhaustive mechanical parsing of all packet headers with a more efficient verification mechanism that checks encryption status through targeted field examination. This substitution reduces processing overhead while maintaining security verification reliability.
Data Source
AI summary
An example security processing method includes receiving data packets at a packet data convergence protocol (PDCP) layer from an upper layer and parsing header information of each of the data packets to determine a length of each of the plurality of headers within the corresponding header information and whether a security header is present or absent in the corresponding data packets. The method further includes identifying corresponding header information of the data packets in which the security header is present based on the determination. The method further includes encrypting, based on the determined header lengths, only each of the plurality of headers of the identified corresponding header information in which the security header is present, and thereafter transmitting the one or more data packets to a lower layer after adding information regarding each of the encrypted headers along with their encryption length into a PDCP header.


