Telecom Partial Integrity Protection for Power and Hardware Limits
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems lack the ability to provide partial integrity protection for user plane data, leading to potential security vulnerabilities and inefficient use of resources such as power consumption and hardware limitations.
Innovation Solution
Implementing partial integrity protection by configuring communication devices to protect only a portion of data packets based on their bit rate, using methods like sequence numbers, timers, and proportion values to manage integrity protection efficiently.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If integrity protection is applied to all data packets, then communication security is improved, but power consumption and hardware strain increase
Solution Approach 1:
The patent segments the data packets into different categories based on their security requirements. Instead of applying integrity protection uniformly to all packets, the system selectively applies protection only to specific packets that require it, determined by configuration parameters such as sequence numbers, timers, or proportion values. This segmentation resolves the contradiction by maintaining security for critical packets while reducing power consumption by excluding non-critical packets from protection.
Solution Approach 2:
The patent implements local quality by applying different integrity protection characteristics to different portions of the data stream. Configuration information allows the system to specify that certain packets (e.g., every Nth packet, or packets within specific time windows) receive integrity protection while others do not. This localized application of protection optimizes the balance between security and power consumption by tailoring protection intensity to specific needs.
2Reliability
If integrity protection is applied to all data packets, then communication security is improved, but hardware resources are overwhelmed
Solution Approach 1:
The patent divides the data packet processing into protected and unprotected segments based on configuration parameters. The network device and terminal device both use the same configuration information to determine which packets require integrity protection. This segmentation reduces hardware strain by limiting the number of packets that undergo complex integrity verification processing, while still maintaining security for the necessary packets.
Solution Approach 2:
The patent applies partial action by implementing integrity protection for only a portion of the data packets rather than all packets. The configuration information specifies the exact scope of protection (e.g., using sequence number ranges, time-based windows, or proportion-based selection). This partial application of integrity protection reduces hardware complexity and processing burden while maintaining adequate security for the protected subset.
3Use of energy by moving object
If partial integrity protection is implemented, then power consumption is reduced, but security coverage is limited
Solution Approach 1:
The patent implements dynamic integrity protection where the scope and intensity of protection can be adjusted based on network conditions, security requirements, and traffic characteristics. The configuration information can be updated to change which packets are protected, allowing the system to adapt to varying security needs while optimizing power consumption. This dynamic approach ensures that security coverage is sufficient for current requirements without wasting power on unnecessary protection.
Solution Approach 2:
The patent uses configurable parameters (sequence numbers, timers, proportion values) to control the scope of integrity protection. By adjusting these parameters, the system can dynamically change the level of security coverage and power consumption. For example, increasing the proportion of protected packets enhances security coverage but increases power consumption, while decreasing it has the opposite effect. This parameter-based control allows flexible optimization of the security-power tradeoff.
Data Source
Figure 1
Figure 2
Figure 3A~3B
AI summary
Example embodiments of the present disclosure relate to partial integrity protection in telecommunication systems. According to embodiments of the present disclosure, there is provided a solution for implementing partial integrity protection. The terminal device receives configuration of the partial integrity protection and applies the integrity protection on a portion of data packets which are communicated between communication devices. In this way, the communication devices can always provide integrity protection for services, regardless of their bit rate. Thus, security of communication can be improved. It also allows to provide integrity protection with limited impacts to power consumption and overheating.