Selective Security Mode for 5G/6G Flow Throughput
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless communication systems face inefficiencies due to duplicate security measures across multiple protocol layers, leading to increased CPU utilization and reduced throughput, especially in high-data-rate environments like 6G networks, which necessitate optimized security protocols to meet the demands of ultra-high data rates and low latency.
Innovation Solution
Implementing selective security modes and flow management strategies, where security is applied only where necessary, such as at the UPF or RAN, based on UE capabilities and packet encryption status, reducing duplicate security and optimizing CPU usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If duplicate security measures are applied across multiple protocol layers, then security coverage is improved, but CPU utilization increases and throughput decreases
Solution Approach 1:
The patent extracts the security function from multiple protocol layers and consolidates it to a specific layer (PDCP layer in 5G NR). Instead of applying security measures at every layer, the solution removes redundant security operations from lower layers while maintaining security at the PDCP layer, thereby reducing CPU overhead while preserving security coverage.
Solution Approach 2:
The patent applies security measures selectively at specific locations (PDCP layer) rather than uniformly across all protocol layers. This localized approach ensures that security is applied only where necessary, avoiding the performance penalty of redundant security operations at multiple layers while maintaining comprehensive security coverage.
2Reliability
If security is applied at multiple protocol layers, then security reliability is improved, but CPU cycles increase
Solution Approach 1:
The patent extracts redundant security operations from multiple protocol layers and consolidates them to the PDCP layer only. This extraction eliminates unnecessary CPU cycles spent on duplicate security processing while maintaining security reliability through proper security implementation at the consolidated layer.
Solution Approach 2:
The patent merges security functions from multiple protocol layers into a single location (PDCP layer). By combining these distributed security operations into one unified security mechanism, the patent reduces the total CPU cycles required while maintaining the same level of security reliability.
3Reliability
If comprehensive security measures are implemented across all layers, then security coverage is improved, but network performance decreases
Solution Approach 1:
The patent extracts redundant security measures from lower protocol layers and removes them, keeping security functionality only at the PDCP layer. This extraction maintains comprehensive security coverage while eliminating the performance overhead associated with multi-layer security implementation.
Solution Approach 2:
The patent applies security measures locally at the PDCP layer rather than distributing them across all protocol layers. This localized security approach ensures comprehensive security coverage is maintained while improving network performance by avoiding redundant security operations at multiple layers.
Data Source
AI summary
The disclosure relates to a fifth generation (5G) communication system or a sixth generation (6G) communication system for supporting higher data rates beyond a fourth generation (4G) communication system such as long term evolution (LTE). A method performed by a core network entity 107 for selecting a selective security mode for applying selective security is provided. The method receives first information block from RAN 106. The first information block includes UE capability to support selective security and preferred selective security mode. Further, core network entity may determine if RAN and core network entity are capable of supporting the preferred selective security mode. Finally, the core network entity applies the preferred selective security on the one or more incoming data packets based on the encryption status of the incoming data packets, when at least one of RAN and core network entity supports the preferred selective security mode.


