User Plane Integrity Protection in EN-DC
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In dual connectivity scenarios, particularly in EN-DC, there is a lack of mechanisms for integrity protecting user plane communications, making them vulnerable to tampering by attackers.
Innovation Solution
Introducing capability signaling to support integrity protection of user plane communications between a wireless communication device and a secondary node, allowing the activation of user plane integrity protection over New Radio (NR) through Non-Access Stratum (NAS) or Radio Resource Control (RRC) signaling, enabling secure transmission of user plane data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If user plane communications are encrypted between wireless communication device and secondary node, then confidentiality is improved, but integrity protection is lacking making communications vulnerable to tampering
Solution Approach 1:
The patent segments the security protection mechanism by introducing separate integrity protection functionality alongside existing encryption. The integrity protection is implemented as a distinct layer that operates independently on user plane data, applying integrity verification separately from the encryption process. This segmentation allows integrity protection to be added without disrupting existing encryption mechanisms.
Solution Approach 2:
The patent implements preliminary action by performing integrity protection calculations (such as generating integrity verification data) before data transmission occurs. The integrity protection is prepared in advance during the security configuration phase, with integrity algorithms and keys being established before actual user plane data flows through the network, ensuring protection is already in place when communications begin.
2Reliability
If capability signaling is introduced to support integrity protection, then security is enhanced, but device complexity increases
Solution Approach 1:
The patent applies universality by designing capability signaling that serves multiple functions: it indicates not only integrity protection support but also coordinates the activation and configuration of integrity protection mechanisms. The same signaling infrastructure used for existing security capabilities is leveraged to convey integrity protection information, allowing one signaling system to handle multiple security-related functions rather than requiring separate dedicated signaling for each security feature.
Solution Approach 2:
The patent implements self-service by enabling the wireless communication device to autonomously indicate its integrity protection capabilities through signaling, allowing the network to automatically configure appropriate security parameters. The device itself provides the capability information without requiring manual configuration or external intervention, and the network uses this self-provided information to automatically establish the security context.
Data Source
AI summary
A wireless communication device (12) transmits, to a network node (18A-1, 18A-2, 18B) in an Evolved Packet System (10A), signaling (14A) indicating a capability (16) of the wireless communication device (12) to support user plane integrity protection over New Radio, NR, in Evolved Universal Terrestrial Radio Access-NR Dual Connectivity, EN-DC. Based on the indicated capability (16), a secondary gNB for EN-DC may activate or deactivate user plane integrity protection over NR in EN-DC.


