UE DNS Traffic Integrity Protection via NAS Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless communication networks lack effective integrity protection for DNS traffic, making them vulnerable to redirection attacks, especially in IoT environments where resource efficiency is crucial.
Innovation Solution
A method and device for configuring User Equipment (UE) to securely exchange DNS messages by using Non-Access Stratum (NAS) messages to convey DNS configuration parameters, enabling integrity protection at the application layer rather than the PDCP layer.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If integrity protection is applied to all data traffic within a PDU session at PDCP layer, then security of DNS traffic is improved, but resource consumption increases
Solution Approach 1:
The patent segments the PDU session into different traffic types (DNS traffic and non-DNS traffic) and applies integrity protection only to DNS traffic using a separate logical channel. This allows selective protection of sensitive DNS packets without extending integrity protection to all data traffic, thereby reducing computational overhead and resource consumption while maintaining security for DNS operations.
Solution Approach 2:
The patent applies different quality of service and security characteristics to different parts of the data traffic. Specifically, DNS traffic receives integrity protection and uses a dedicated logical channel, while non-DNS traffic uses the standard user plane without integrity protection. This localized application of security measures optimizes resource usage by protecting only the sensitive portion of traffic.
2Power
If integrity protection is not enabled for LTE DRBs, then computation power is reduced, but security vulnerability increases
Solution Approach 1:
The patent introduces a dedicated logical channel specifically for DNS traffic that operates independently from the standard LTE DRB user plane. This segmentation allows integrity protection to be applied only to DNS packets through this separate channel, avoiding the need to enable computationally intensive integrity protection across all user plane traffic, thus balancing security needs with computation power constraints.
3Reliability
If integrity protection is applied at PDCP layer for entire PDU session, then DNS traffic protection is achieved, but resource waste occurs
Solution Approach 1:
The patent segments DNS traffic from other user plane traffic by introducing a dedicated logical channel for DNS packets. This allows the network to apply integrity protection selectively only to DNS traffic flowing through this dedicated channel, rather than wasting resources applying protection to all traffic types within the PDU session. The segmentation enables precise resource allocation matching security requirements.
Solution Approach 2:
The patent implements local quality differentiation by providing enhanced security characteristics (integrity protection) specifically to DNS traffic through the dedicated logical channel, while other traffic types maintain standard transmission without integrity protection. This localized approach ensures DNS protection is achieved without the resource waste of applying universal integrity protection across the entire PDU session.
Data Source
Figure 1A~2
Figure 3A~4
Figure 5~6
AI summary
Disclosed herein are a communication technique for merging, with an IoT technology, a 5G communication system for supporting a data transmission rate higher than that of a 4G system; and a system therefor. Embodiments herein disclose a method of protecting sensitive user plane traffic in an User Equipment (UE) (100), the method comprising: transmitting, to a network (200), by the UE (100) a first NAS message comprising an indicator indicating that the UE (200) supports of a secure channel for domain name system (DNS); receiving, from the network (200), by the UE (100) a second NAS message including DNS server security information in response to transmitting the first NAS message; and transmitting, to the network (200), by the UE (100) the DNS over the secure channel based on the DNS server security information.