User Plane Control Data Security Across Wireless Protocol Layers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing diversification of services in wireless communication systems has heightened the need for improved network security, particularly in securing transmission of user plane control data.

Innovation Solution

A communication method involving security processing, including encryption and/or integrity protection, is applied to user plane control data at various protocol layers such as SDAP, PDCP, RLC, and MAC, with indication information to determine and perform security processing on specific control data types.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security processing (encryption and integrity protection) is applied to user plane control data, then communication security is improved, but processing time and system complexity increase

Engineering Contradiction:
Improvecommunication securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Security processing parameters (encryption algorithms, integrity protection methods) are pre-configured and stored in the communication apparatus. When user plane control data needs security processing, the pre-configured parameters are directly applied without requiring real-time security parameter negotiation or computation, thereby reducing processing time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security processing is segmented into distinct functional modules: encryption processing module and integrity protection processing module. Each module handles specific security operations independently, allowing parallel processing and optimizing the overall security processing efficiency without compromising security strength.

Inventive Principle:
Principle #1Segmentation

2Reliability

If security processing is applied to all control data types, then communication security is improved, but device complexity and processing overhead increase

Engineering Contradiction:
Improvecommunication securityVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Different security processing policies are applied to different control data types based on their specific security requirements. The determination module identifies the type of control data and selects appropriate security processing parameters from pre-configured options, applying security processing only where necessary rather than uniformly to all control data, thus reducing overall system complexity while maintaining security for critical data.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

Security processing is applied selectively to specific control data types that require it, rather than to all control data. The system identifies and applies security processing only to control data where security threats are most probable or impact is most severe, reducing processing complexity and overhead while maintaining adequate security coverage.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If multiple protocol layers (SDAP, PDCP, RLC, MAC) perform security processing, then security coverage is improved, but processing time and resource consumption increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidtransmission efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Each protocol layer (SDAP, PDCP, RLC, MAC) has pre-configured security processing parameters specific to its layer characteristics and security requirements. This allows each layer to independently apply appropriate security processing without real-time coordination, reducing inter-layer communication overhead and processing time while maintaining comprehensive security coverage across all layers.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12477339B2Communication method and apparatus
Publication Date: 2025.11.18 HUAWEI TECH CO LTD
  • US12477339B2 patent drawing
  • US12477339B2 patent drawing
  • US12477339B2 patent drawing

AI summary

This application provides a communication method and apparatus. A transmitting apparatus performs first security processing on first control data of a user plane to obtain second control data. The first security processing comprises at least one of encryption processing or integrity protection processing. Furthermore, a packet header of the second control data comprises first security indication information, and the first security indication information indicates that the second control data underwent the first security processing. The transmitting apparatus then sends the second control data to a receiving apparatus. The receiving apparatus performs at least one of decryption processing or integrity verification processing on the second control data. In this way, network security is improved.