User Plane Control Data Security Across Wireless Protocol Layers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing diversification of services in wireless communication systems has heightened the need for improved network security, particularly in securing transmission of user plane control data.
Innovation Solution
A communication method involving security processing, including encryption and/or integrity protection, is applied to user plane control data at various protocol layers such as SDAP, PDCP, RLC, and MAC, with indication information to determine and perform security processing on specific control data types.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security processing (encryption and integrity protection) is applied to user plane control data, then communication security is improved, but processing time and system complexity increase
Solution Approach 1:
Security processing parameters (encryption algorithms, integrity protection methods) are pre-configured and stored in the communication apparatus. When user plane control data needs security processing, the pre-configured parameters are directly applied without requiring real-time security parameter negotiation or computation, thereby reducing processing time while maintaining security.
Solution Approach 2:
The security processing is segmented into distinct functional modules: encryption processing module and integrity protection processing module. Each module handles specific security operations independently, allowing parallel processing and optimizing the overall security processing efficiency without compromising security strength.
2Reliability
If security processing is applied to all control data types, then communication security is improved, but device complexity and processing overhead increase
Solution Approach 1:
Different security processing policies are applied to different control data types based on their specific security requirements. The determination module identifies the type of control data and selects appropriate security processing parameters from pre-configured options, applying security processing only where necessary rather than uniformly to all control data, thus reducing overall system complexity while maintaining security for critical data.
Solution Approach 2:
Security processing is applied selectively to specific control data types that require it, rather than to all control data. The system identifies and applies security processing only to control data where security threats are most probable or impact is most severe, reducing processing complexity and overhead while maintaining adequate security coverage.
3Reliability
If multiple protocol layers (SDAP, PDCP, RLC, MAC) perform security processing, then security coverage is improved, but processing time and resource consumption increase
Solution Approach 1:
Each protocol layer (SDAP, PDCP, RLC, MAC) has pre-configured security processing parameters specific to its layer characteristics and security requirements. This allows each layer to independently apply appropriate security processing without real-time coordination, reducing inter-layer communication overhead and processing time while maintaining comprehensive security coverage across all layers.
Data Source
AI summary
This application provides a communication method and apparatus. A transmitting apparatus performs first security processing on first control data of a user plane to obtain second control data. The first security processing comprises at least one of encryption processing or integrity protection processing. Furthermore, a packet header of the second control data comprises first security indication information, and the first security indication information indicates that the second control data underwent the first security processing. The transmitting apparatus then sends the second control data to a receiving apparatus. The receiving apparatus performs at least one of decryption processing or integrity verification processing on the second control data. In this way, network security is improved.


