Data Verification Between UE and UPF in 5G Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 5G communications, there is no effective check mechanism for user plane data integrity protection when the security termination point is on a User Plane Function (UPF), leading to potential data plane attacks as there is no mechanism to verify the consistency of data packets between User Equipment (UE) and UPF without enabled integrity protection on the radio air interface.
Innovation Solution
A data check method that involves obtaining counter values from both UE and UPF during data transmission, comparing them to determine if they match, and sending a response message to the session management network element if they do not, thereby indicating potential data plane attacks or abnormalities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If user plane integrity protection is not enabled on the radio air interface, then device complexity is reduced, but data reliability deteriorates due to lack of check mechanism for data transmitted between UE and UPF
Solution Approach 1:
The patent introduces a session management network element as an intermediary that coordinates counter value verification between UE and UPF. This mediator enables data integrity checking without requiring complex integrity protection mechanisms on the radio air interface itself, thus resolving the contradiction between reduced device complexity and maintained data reliability.
Solution Approach 2:
The patent implements a feedback mechanism where counter values are exchanged and verified between UE, gNB, and UPF through the session management network element. This feedback loop allows the system to detect and respond to data transmission anomalies without implementing complex proactive integrity protection, balancing simplicity with reliability.
2Reliability
If counter value verification is implemented between UE and UPF, then data reliability is improved, but device complexity increases due to additional check mechanisms
Solution Approach 1:
The session management network element performs multiple functions including counter value verification, anomaly detection, and coordinate response generation. By consolidating these functions in a single network element rather than distributing complexity across multiple devices, the patent achieves improved data reliability while minimizing overall device complexity.
Solution Approach 2:
The gNB automatically performs counter value verification and anomaly detection without requiring additional complex processing at the UE or UPF. The existing network elements utilize their current capabilities to perform verification functions, reducing the need for new complex mechanisms while maintaining high data reliability.
3Reliability
If data check procedure is continuously performed, then data reliability is maintained, but productivity decreases due to additional processing overhead
Solution Approach 1:
The patent implements periodic counter value verification at specific intervals or trigger events rather than continuous checking. This periodic approach maintains data integrity through regular verification while minimizing processing overhead and avoiding constant interruption of data transmission, thus preserving productivity.
Solution Approach 2:
The verification process skips detailed examination of normal traffic patterns and focuses only on anomaly detection through counter value comparison. This selective verification approach maintains high data reliability by catching anomalies while rushing through normal data transmission without unnecessary processing delays.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Embodiments of this application provide a data check method, a data check apparatus, and a storage medium. The data check method includes: obtaining a first counter value and a second counter value, where the first counter value is a value obtained by performing counting by UE during data transmission between the UE and a UPF entity, and the second counter value is a value obtained by performing counting by the UPF entity during the data transmission between the UE and the UPF entity; determining whether the first counter value matches the second counter value; and if the first counter value does not match the second counter value, sending a response message to a session management network element, to protect data transmitted between the UE and the UPF when user plane integrity protection is not enabled on a radio air interface. Whether there is a data plane attack is determined by determining whether quantities of uplink and downlink data packets sent or received by the UE and the UPF are the same.