Signaling Plane Security for Mission Critical Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional MCData communication systems provide end-to-end security only for the media plane, leaving the signaling plane unprotected, which is critical for secure mission-critical data and video communications, especially in public safety networks.
Innovation Solution
A method and system that apply encryption and integrity protection to MC signaling parameters and data payloads using a signaling plane security context for one-to-one and group communications, ensuring end-to-end security over the signaling plane by utilizing private call keys for one-to-one communications and symmetric group master keys for group communications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If end-to-end security is provided only for media plane in conventional MCData communication systems, then the implementation complexity is reduced, but the security coverage is insufficient as signaling plane remains unprotected
Solution Approach 1:
The patent segments the security protection mechanism into two distinct parts: media plane security (existing) and signaling plane security (new). By applying encryption and integrity protection separately to signaling parameters and data payloads using different security contexts, the patent expands security coverage to the signaling plane while maintaining the existing media plane security architecture, thus improving overall security coverage without completely redesigning the system.
Solution Approach 2:
The patent introduces signaling plane security context as an intermediary layer between the existing media plane security mechanism and the unprotected signaling plane. This intermediary provides the necessary encryption and integrity protection for signaling data, enabling secure signaling plane communication while leveraging the existing security infrastructure, thereby improving security coverage with controlled complexity.
2Reliability
If encryption and integrity protection are applied to both signaling parameters and data payloads, then the security and compliance in public safety networks is enhanced, but the processing overhead increases
Solution Approach 1:
The patent applies different security measures to different parts of the data based on their sensitivity and requirements. Signaling parameters are protected using signaling plane security context with encryption and integrity protection, while data payloads are protected using media plane security context. This localized application of security measures ensures that each component receives appropriate protection levels, enhancing overall security and compliance while optimizing processing overhead by avoiding uniform application of the most stringent measures to all data.
Data Source
AI summary
The present disclosure relates to a pre-5th-Generation (5G) or 5G communication system to be provided for supporting higher data rates Beyond 4th-Generation (4G) communication system such as Long Term Evolution (LTE). Embodiments herein provide method and system for end-to-end security over signaling plane in a mission critical data (MCData) communication system. The proposed method includes various ways of securing MCData data payload transmitted over signaling plane using short data service (SDS). The proposed method allows usage of multiple security keys to encrypt the MCData SDS message as per the requirements. Various Keys such as, signaling plane key or media plane key or a dedicated MCData data payload signaling key can be used independently or in a combination thereof to achieve the desired security context. The proposed method allows protection of all the application level components with the signaling plane security context.


