Terminal Device SDT Malicious Data Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Terminal devices operating in an inactive state during Small Data Transmission (SDT) procedures are vulnerable to malicious transmissions of 'garbage' data from attacker network nodes, as they cannot distinguish between genuine and malicious data until the end of the SDT procedure, leading to potential buffer filling and data exposure.

Innovation Solution

The terminal device is configured to detect and avoid processing malicious data transmissions by checking if the radio bearer is configured for the SDT procedure and performing security actions such as discarding or suspending data processing for non-configured bearers, and maintaining a list of trusted network nodes to authenticate integrity-protected bearers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the terminal device processes all received data during SDT procedure, then data communication completeness is improved, but security against malicious transmissions deteriorates

Engineering Contradiction:
Improvedata communication completenessVSAvoidvulnerability to malicious transmissions
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The terminal device performs preliminary actions by maintaining a list of trusted network nodes before receiving data during SDT procedure. This pre-established trust relationship allows the device to proactively identify and reject data from untrusted sources, preventing security issues before they occur while maintaining normal data processing for legitimate sources

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary verification mechanism where the terminal device checks the source of received data against its trusted network node list before processing. This intermediary step acts as a filter between raw data reception and data processing, allowing the system to maintain communication completeness for trusted sources while blocking malicious transmissions

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If the terminal device discards data from non-configured bearers, then security against garbage data is improved, but risk of discarding legitimate data increases

Engineering Contradiction:
Improveprotection from garbage dataVSAvoidlegitimate data reception
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The terminal device performs preliminary configuration of SDT procedure and maintains a list of trusted network nodes before data transmission. This pre-configuration establishes clear criteria for identifying legitimate data sources, allowing the device to confidently discard data from non-configured bearers without risking loss of legitimate communications

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a feedback mechanism where the terminal device continuously monitors received data against its trusted network node list and SDT configuration. This feedback loop allows the device to dynamically adjust data handling decisions, ensuring that only data from verified trusted sources is processed while maintaining the ability to accept legitimate data that meets the established criteria

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240259807A1Attacker identification during small data transmission
Publication Date: 2024.08.01 NOKIA TECHNOLOGIES OY
  • US20240259807A1 patent drawing
  • US20240259807A1 patent drawing
  • US20240259807A1 patent drawing

AI summary

According to an aspect, there is provided a terminal device for performing the following. The terminal device obtains, when the terminal device is in an inactive state while a small data transmission, SDT, procedure is ongoing, information that indicates transmission of a data unit over a radio bearer to the terminal device. The terminal device checks whether or not the radio bearer is configured for the SDT procedure. The terminal device determines whether or not to avoid further processing and/or decoding of the data unit based at least on the checking.