Sie befinden Sich nicht im Netzwerk der Universität Paderborn. Der Zugriff auf elektronische Ressourcen ist gegebenenfalls nur via VPN oder Shibboleth (DFN-AAI) möglich. mehr Informationen...
User plane (UP) security is used to provide integrity and confidentiality of user data between user equipment (UE) and radio access network (RAN). However, UP security significantly degrades UP throughput because it consumes notable processing resources to compute complex cryptography algorithms in packet data convergence protocol (PDCP) at UE and RAN. In this paper, we propose `Selective UP Security,' which is application security-aware UP security to reduce the processing overhead of duplicated security protection and to enhance both UE and RAN throughput. In order to eliminate duplicated security of the PDCP packet, Selective UP Security firstly identifies the encrypted application traffic flow and then applies additional security to non-encrypted parts of the PDCP packet. We build a network testbed to evaluate our proposed scheme by utilizing open sources including UERANSIM, OpenAirInterface (OAI), and Open5GS. Experiment results demonstrate that our scheme can reduce security processing overheads of the PDCP layer by approximately 80% and processing overhead by approximately 30% at gNB and UE, and provide UP throughput enhancement by approximately 40%.