T6 Interface for Offloading MTC Traffic from MME
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current solutions for the T5 interface in 3GPP systems face issues such as increased load on the NAS layer and potential security threats due to concentrated device triggering and small data transmission, leading to node overload and vulnerability to attacks.
Innovation Solution
A new interface, T6, is introduced between the MTC-IWF and the eNB, allowing for secure and efficient communication by offloading burdens from the MME, preventing Denial-of-Service attacks, and enabling independent security for device triggering and small data transmission, with the MTC-IWF acting as a central point for MTC communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If device triggering and small data transmission are concentrated through the T5 interface at the MME, then MTC communication is enabled, but the MME becomes overloaded and vulnerable to attacks
Solution Approach 1:
The patent introduces a new network entity called the MTC Gateway that acts as an intermediary between the MME and MTC devices. This gateway handles device triggering and small data transmission, preventing these functions from overloading the MME. The gateway serves as a mediator that offloads processing tasks and protects the core network elements from direct exposure to MTC traffic bursts and potential attacks.
Solution Approach 2:
The patent segments the MTC handling functions by separating device triggering and small data transmission from the MME's core mobility management functions. This segmentation is achieved by introducing dedicated interfaces (T6 for device triggering, T7 for small data) that route traffic through the MTC Gateway, thereby dividing the system into specialized components with distinct responsibilities.
2Reliability
If NAS security is used for small data transmission, then security is provided, but the load on the NAS layer and MME increases
Solution Approach 1:
The MTC Gateway acts as an intermediary that handles security processing for small data transmissions. By offloading security verification and NAS message processing to the gateway, the MME's NAS layer burden is reduced while maintaining security through the gateway's verification of authorization and integrity checks.
Solution Approach 2:
The patent extracts security processing functions from the MME's NAS layer and relocates them to the MTC Gateway. This extraction includes authorization verification, message integrity checking, and security context management, thereby reducing the complexity and load on the NAS layer while maintaining security through dedicated security handling at the gateway.
3Productivity
If the current T5 interface solution is used, then MTC communication is enabled, but authorization on SCS is insufficient leading to network vulnerabilities
Solution Approach 1:
The MTC Gateway serves as a protective intermediary between the SCS and the core network. It implements robust authorization checks, validates service requests, and filters malicious traffic before it reaches network elements. This intermediary position allows the system to maintain MTC communication functionality while protecting against attacks through enhanced authorization and validation mechanisms.
Solution Approach 2:
The patent implements preliminary security measures at the MTC Gateway including pre-verification of SCS authorization, validation of device credentials, and filtering of suspicious traffic patterns before they can reach vulnerable network elements. This preliminary anti-action prevents potential attacks from propagating into the core network while allowing legitimate MTC communications to proceed.
Data Source
AI summary
In order for making MTC more efficient and/or secure, a base station forming a communication system connects a UE to a core network. A node serves as an entering point to the core network for a service provider, and transmits traffic between the service provider and the UE. The node establishes, as a connection to the base station, a first connection for directly transceiving messages between the node and the base station. Alternatively, the node establishes a second connection for transparently transceiving the messages through a different node that is placed within the core network and has established a different secure connection to the base station.


