UE DNS Traffic Integrity Protection via NAS Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication networks lack effective integrity protection for DNS traffic, making them vulnerable to redirection attacks, especially in IoT environments where resource efficiency is crucial.

Innovation Solution

A method and device for configuring User Equipment (UE) to securely exchange DNS messages by using Non-Access Stratum (NAS) messages to convey DNS configuration parameters, enabling integrity protection at the application layer rather than the PDCP layer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If integrity protection is applied to all data traffic within a PDU session at PDCP layer, then security of DNS traffic is improved, but resource consumption increases

Engineering Contradiction:
Improvesecurity of DNS trafficVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the PDU session into different traffic types (DNS traffic and non-DNS traffic) and applies integrity protection only to DNS traffic using a separate logical channel. This allows selective protection of sensitive DNS packets without extending integrity protection to all data traffic, thereby reducing computational overhead and resource consumption while maintaining security for DNS operations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different quality of service and security characteristics to different parts of the data traffic. Specifically, DNS traffic receives integrity protection and uses a dedicated logical channel, while non-DNS traffic uses the standard user plane without integrity protection. This localized application of security measures optimizes resource usage by protecting only the sensitive portion of traffic.

Inventive Principle:
Principle #3Local quality

2Power

If integrity protection is not enabled for LTE DRBs, then computation power is reduced, but security vulnerability increases

Engineering Contradiction:
Improvecomputation powerVSAvoidsecurity vulnerability
Core Design Contradiction:
PowerVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a dedicated logical channel specifically for DNS traffic that operates independently from the standard LTE DRB user plane. This segmentation allows integrity protection to be applied only to DNS packets through this separate channel, avoiding the need to enable computationally intensive integrity protection across all user plane traffic, thus balancing security needs with computation power constraints.

Inventive Principle:
Principle #1Segmentation

3Reliability

If integrity protection is applied at PDCP layer for entire PDU session, then DNS traffic protection is achieved, but resource waste occurs

Engineering Contradiction:
ImproveDNS traffic protectionVSAvoidresource waste
Core Design Contradiction:
ReliabilityVSLoss of substance

Solution Approach 1:

The patent segments DNS traffic from other user plane traffic by introducing a dedicated logical channel for DNS packets. This allows the network to apply integrity protection selectively only to DNS traffic flowing through this dedicated channel, rather than wasting resources applying protection to all traffic types within the PDU session. The segmentation enables precise resource allocation matching security requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality differentiation by providing enhanced security characteristics (integrity protection) specifically to DNS traffic through the dedicated logical channel, while other traffic types maintain standard transmission without integrity protection. This localized approach ensures DNS protection is achieved without the resource waste of applying universal integrity protection across the entire PDU session.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP4111721B1Method and device for protecting sensitive user plane traffic
Publication Date: 2025.04.09 SAMSUNG ELECTRONICS CO LTD
  • EP4111721B1 patent drawingFigure 1A~2
  • EP4111721B1 patent drawingFigure 3A~4
  • EP4111721B1 patent drawingFigure 5~6

AI summary

Disclosed herein are a communication technique for merging, with an IoT technology, a 5G communication system for supporting a data transmission rate higher than that of a 4G system; and a system therefor. Embodiments herein disclose a method of protecting sensitive user plane traffic in an User Equipment (UE) (100), the method comprising: transmitting, to a network (200), by the UE (100) a first NAS message comprising an indicator indicating that the UE (200) supports of a secure channel for domain name system (DNS); receiving, from the network (200), by the UE (100) a second NAS message including DNS server security information in response to transmitting the first NAS message; and transmitting, to the network (200), by the UE (100) the DNS over the secure channel based on the DNS server security information.