Selective Tunnel Encryption for Multi-Access User Equipment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In hybrid wireless networks, existing methods for securing data traffic through encrypted tunnels lead to resource over-utilization due to the unnecessary use of computational and memory resources, especially when data is already encrypted, as they apply a uniform high security level to all communication links regardless of their trustworthiness.

Innovation Solution

A method that assesses the trustworthiness of each communication link and dynamically adjusts the security level based on the type of trustiness, allowing for different security levels on different communication links, using an algorithm to determine the appropriate security level for each link, thereby optimizing resource usage by reducing unnecessary encryption and tunneling.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a uniform maximum security level is applied to all communication links, then security is ensured, but computational and memory resources are over-utilized

Engineering Contradiction:
ImprovesecurityVSAvoidcomputational and memory resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies different security levels to different communication links based on their individual trustworthiness characteristics. Instead of using a uniform maximum security level across all links, the system assesses each link's security requirements locally and applies appropriate encryption only where needed, thereby reducing overall computational and memory resource consumption while maintaining adequate security.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically changes the security parameter (encryption level) based on the trustworthiness assessment of each communication link. When a link is deemed trustworthy, the security level is reduced or encryption is disabled, allowing the system to adapt resource consumption to actual security needs rather than maintaining constant maximum security levels.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If encryption is applied to all communication links, then data protection is improved, but battery life in user equipment is reduced

Engineering Contradiction:
Improvedata protectionVSAvoidbattery life
Core Design Contradiction:
ReliabilityVSDuration of action of moving object

Solution Approach 1:

The patent implements selective encryption based on the specific characteristics of each communication link. By assessing the trustworthiness of individual links and applying encryption only where necessary, the system reduces the overall computational burden on the user equipment, thereby conserving battery power while maintaining data protection where it is actually needed.

Inventive Principle:
Principle #3Local quality

3Reliability

If high security level is maintained for all links, then security requirements are met, but data throughput is reduced

Engineering Contradiction:
Improvesecurity requirementsVSAvoiddata throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies different security levels to different communication links based on their trustworthiness assessment. For links that are assessed as trustworthy, the security level is reduced or encryption is disabled, which removes the overhead associated with encryption/decryption operations and thereby increases data throughput for those specific links while maintaining adequate security where risks exist.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3923611B1Selectable tunnel encryption level management for multi access user equipment
Publication Date: 2024.12.11 DEUTSCHE TELEKOM AG
  • EP3923611B1 patent drawingFigure 1
  • EP3923611B1 patent drawingFigure 2
  • EP3923611B1 patent drawingFigure 3

AI summary

A method and a system for ensuring secure wireless communication of a User Equipment, UE, in a communication system, wherein the communication system comprises an User Equipment and a server, in particular a server of a network provider, configured to communicate data of a data traffic with each other over a network via a first tunneled communication link of a first access technology and a second tunneled communication link of a second access technology; the method comprises the steps of: Retrieving information about a type of trustiness of the first communication link of the first access technology and about the second communication link of the second access technology; Providing the information about the type of trustiness as a first input parameter to an algorithm implemented on a computing unit of the UE and/or the server, wherein the algorithm is configured to calculate encryption security levels, wherein as a first option: setting-up a uniform encryption security level of the first tunneled communication link and the second tunneled communication link based on the information about the type of trustiness or as a second option: setting-up a first encryption security level of the first tunneled communication link and a second first encryption security level of the second tunneled communication link based on the information about the type of trustiness. (see Fig. 4)