Session Granularity Security Activation for Wireless UEs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication systems provide security settings on a one-shot basis for all sessions associated with a device, which may not adequately meet the varying security requirements of different sessions, leading to inefficient use of network resources and decreased performance.

Innovation Solution

A system and method for security activation with session granularity, where security keys and parameters are derived and applied on a per-session basis, allowing for tailored security settings for each radio bearer within a PDU session, using messages like SecurityModeCommand and RRCConnectionReconfiguration to configure and initiate security for signaling and data radio bearers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If security settings are applied uniformly to all sessions associated with a device, then device-level security is simplified and easier to manage, but session-specific security requirements cannot be met and network resources are used inefficiently

Engineering Contradiction:
Improvesession-specific security configurationVSAvoidsecurity activation mechanism
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments security activation into two distinct phases: device-level security activation for signaling radio bearers (SRBs) and session-level security activation for data radio bearers (DRBs). This segmentation allows uniform device-level security while enabling customized session-specific security parameters, resolving the contradiction between adaptability and complexity by organizing security management hierarchically.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dynamic security parameter configuration where security parameters for DRBs can be adjusted on a per-session basis after initial device security activation. This dynamic approach allows the system to adapt security settings to specific session requirements without reconfiguring the entire device security framework, maintaining simplicity while enabling versatility.

Inventive Principle:
Principle #15Dynamics

2Reliability

If highest security levels are applied to all sessions, then security coverage is maximized, but processing time and system overhead increase

Engineering Contradiction:
Improvesecurity protection levelVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by allowing different security parameter configurations for different sessions (DRBs) based on their specific requirements. Instead of uniformly applying highest security levels to all sessions, the system configures security parameters locally for each session, providing adequate security protection only where needed and reducing unnecessary processing overhead for sessions with lower security requirements.

Inventive Principle:
Principle #3Local quality

3Productivity

If session granularity security activation is implemented, then security efficiency is improved and processing overhead is reduced, but the security activation mechanism becomes more complex

Engineering Contradiction:
Improvesecurity processing efficiencyVSAvoidsecurity parameter management
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by establishing device-level security activation and SRB security configuration before session-specific security parameters are needed. This preliminary security framework is in place before data sessions are established, allowing session-specific parameters to be applied efficiently without requiring complex real-time security negotiations, thus improving processing efficiency while managing complexity through staged configuration.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11856396B2System and method for security activation with session granularity
Publication Date: 2023.12.26 FUTUREWEI TECHNOLOGIES INC
  • US11856396B2 patent drawing
  • US11856396B2 patent drawing
  • US11856396B2 patent drawing

AI summary

A method for operating a user equipment (UE) includes deriving security keys for a signaling radio bearer (SRB) in accordance with a first message received from an access node, initiating security for the SRB in accordance with the first message, receiving, from the access node, a second message including at least one security parameter for at least one data radio bearer (DRB), wherein the at least one security parameter is associated with a session that includes the at least one DRB, and wherein the second message is secured with the security keys for the SRB, and initiating security for the at least one DRB in accordance with the at least one security parameter.