V2X Sidelink Security Configuration for Multi-Service UE Links

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication systems face challenges in supporting Vehicle-to-Everything (V2X) services over a single one-to-one sidelink communication link, particularly in establishing secure and efficient communication protocols for unicast and multicast operations, security associations, and maintaining links in V2X contexts.

Innovation Solution

The implementation of a method and apparatus for UE (User Equipment) to support multiple services on a one-to-one sidelink communication link, involving security configuration negotiation, encryption/decryption, and the use of RRC signaling for unicast/multicast communication management, with enhanced security protocols and service announcements to facilitate V2X service establishment and maintenance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a single one-to-one sidelink communication link is used for V2X services, then resource utilization and communication efficiency are improved, but supporting multiple services with different security requirements becomes difficult

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidmulti-service support capability
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent segments the security configuration into service-specific security configurations, where each V2X service can have its own security parameters (encryption algorithms, key management, authentication methods). This allows a single communication link to carry multiple services with different security requirements by applying appropriate security policies to each service's data stream.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal security management mechanism that can handle multiple service types on a single link. The security configuration negotiation framework enables the link to adaptively apply different security schemes for different services, making the single link multi-functional in terms of service support while maintaining security isolation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If service-specific security configurations are implemented for each V2X service, then security requirements for different services are met, but negotiation overhead and setup complexity increase

Engineering Contradiction:
Improvesecurity assuranceVSAvoidsecurity configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs security configuration negotiation as a preliminary action during service establishment or link setup phase. By negotiating and agreeing on service-specific security configurations in advance, the system avoids complex real-time security decision-making and reduces runtime complexity. The pre-negotiated security parameters are then applied automatically to the corresponding services.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables UEs to autonomously negotiate and configure security parameters for different services without requiring network intervention for each service setup. The UE's protocol stack automatically manages service-specific security configurations, selecting and applying appropriate security schemes based on service requirements, thereby reducing overall system complexity while maintaining high security assurance.

Inventive Principle:
Principle #25Self-service

3Reliability

If security configuration is negotiated for each service, then service security is enhanced, but communication setup time increases

Engineering Contradiction:
Improveservice securityVSAvoidservice setup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges the security configuration negotiation with the existing service establishment or link setup procedures. Instead of treating security negotiation as a separate sequential step, the security configuration is integrated into the service setup flow, allowing parallel processing of service parameters and security parameters. This reduces the overall setup time while still providing service-specific security.

Inventive Principle:
Principle #5Merging (Combining)

4Productivity

If a single communication link is used for multiple V2X services, then resource efficiency is improved, but security isolation between services becomes challenging

Engineering Contradiction:
Improveresource efficiencyVSAvoidsecurity isolation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies local quality by implementing service-specific security configurations for different V2X services on the same physical link. Each service's data stream is processed with its own security parameters (encryption keys, algorithms, authentication methods), creating logical security isolation. This allows resource efficiency of a single link while maintaining the security isolation equivalent to multiple separate links through virtualization of security contexts.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11457355B2Method and apparatus for supporting vehicle-to-everything (V2X) services on single one-to-one sidelink communication link in a wireless communication system
Publication Date: 2022.09.27 ASUSTEK COMPUTER INC
  • US11457355B2 patent drawing
  • US11457355B2 patent drawing
  • US11457355B2 patent drawing

AI summary

A method and apparatus are disclosed from the perspective of a first UE (User Equipment) to support multiple services on a one-to-one sidelink communication link between the first UE and a second UE. In one embodiment, the first UE initiates a first service. The first UE also establishes the one-to-one sidelink communication link for the first service. Furthermore, the first UE negotiates a security configuration with the second UE for encrypting or decrypting data from the first service. In addition, the first UE initiates a second service. The first UE also encrypts or decrypts data from the second service with the security configuration used by the first service.