CP mode reconstruction optimization method for Internet of Things

By using S-TMSI and core network to verify security in NB-IoT system, and converting RRC Reestablishment to RRC Setup messages when reconstruction fails, the problem of NAS layer security verification failure in CP mode reconstruction process is solved, and the effect of fast connection recovery, reduced power consumption and improved network reliability is achieved.

CN120050613APending Publication Date: 2025-05-27SHANGHAI PENGHU WUYU TECHNOLOGY DEVELOPMENT CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510235050.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

In NB-IoT system, the CP mode reconstruction process fails due to the NAS layer security verification failure, which affects the real-time service, increases device power consumption, and may cause signaling storms and network congestion, reducing users' trust in IoT services.

Method used

By using S-TMSI in the base station to identify the terminal device and verify security with the help of the core network, if the verification fails, the RRC Reestablishment message is converted into an RRC Setup message, reducing signaling overhead and device power consumption, and quickly recovering the connection state.

Benefits of technology

It realizes rapid connection recovery, reduce latency and power consumption, improve network reliability and user experience, reduce device power consumption and avoid signaling storms in the event of reconstruction failure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050613A_ABST
    Figure CN120050613A_ABST
Patent Text Reader

Abstract

The invention discloses a CP mode reconstruction optimization method for the Internet of Things, and the method comprises the following steps: S1, a terminal initiates a reconstruction process, and the terminal sends an RRC Reestabilistic Request message to a base station; s2, after the base station receives the RRC Reestablistic Request message, the terminal equipment is identified by means of the S-TMSI (Service-Temporary Mobile Subscriber Identity); s3, according to the fact that the S-TMSI is unique in the MME Group, the design not only can reduce the use of permanent identifiers, but also can enhance the characteristics of security, and the base station matches the terminal with the S-TMSI and searches the context of the user at the same time; s4, after the base station is matched with the S-TMSI terminal, the base station sends an eNB CP (evolved Node B) Relocation Indication message and carries a UL CP Security Indication field, and the UL CP Security Indication field is used for verifying the security by means of a core network; s5, if a scene that security verification of the terminal matched with the S-TMSI and a core network NAS layer fails occurs, taking the S-TMSI as a first layer of screening, and taking the S-TMSI as a target terminal for recovering the RRC connection; the problem that the trust degree of the user to the Internet of Things service is reduced is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of CP mode reconstruction for the Internet of Things, and in particular to a method for optimizing CP mode reconstruction for the Internet of Things. Background Art

[0002] In the NB-IoT (NarrowBand-IoT) narrowband Internet of Things system, NB-IoT devices usually send small data packets frequently. The user plane (UP mode) of traditional LTE needs to establish a complete radio bearer (DRB), resulting in excessive signaling overhead, which does not meet the requirements of low power consumption and low complexity.

[0003] In order to achieve the goal of reducing power consumption and resource consumption and optimize the complex UE context establishment process in the traditional process, the CP mode transmits data by multiplexing control plane signaling (such as NAS messages), which simplifies the data transmission process, reduces signaling storms, improves network capacity, significantly reduces device activation time, and extends battery life.

[0004] NB-IoT devices are usually deployed in weak signal environments, which are prone to wireless link failures due to signal attenuation or interference. To cope with the instability of wireless links, a reconstruction mechanism is introduced for the CP mode. The reconstruction process allows devices to quickly restore connections after link interruption, avoiding the high cost of completely re-establishing connections. The reconstruction process reduces signaling overhead and power consumption by reusing some existing contexts, significantly reducing the number of signaling interactions and device power consumption.

[0005] Since the security of the access layer (AS) is not established in the reconstruction under CP mode, the security key of the non-access layer (NAS) is borrowed to ensure the security of communication. However, due to the deviation of NAS COUNT and the error of DIRECTION setting, the security verification of UE and core network will be affected, resulting in the failure of the reconstruction process. The failure of the reconstruction process will lead to service interruption, and key data (such as alarm information and billing data) cannot be uploaded in time, affecting the real-time performance of the application; after the reconstruction fails, the device may frequently attempt to reconnect, and the invalid reconstruction attempts will occupy wireless resources (such as PRACH and PDCCH), reduce the available resources of other devices, lead to PRACH channel congestion, aggravate the network load, cause signaling storm and network congestion, and waste network resources; repeated attempts of the device will also significantly increase power consumption and frequent state switching. Battery energy is consumed; business availability is reduced, service reliability is impaired, and user experience is degraded, resulting in a decrease in user trust in IoT services; therefore, a reliable reconstruction process and reconstruction optimization are necessary. Summary of the invention

[0006] In order to solve the problems existing in the prior art, the present invention provides a method for reconstructing and optimizing the CP mode for the Internet of Things, which solves the problem of decreased trust of users in the Internet of Things services.

[0007] The technical solution provided by the present invention is as follows:

[0008] A method for CP mode reconstruction optimization for the Internet of Things, comprising the following steps:

[0009] Step S1: The terminal initiates the reestablishment process and sends an RRC Reestablishment Request message to the base station;

[0010] Step S2: After receiving the RRC Reestablishment Request message, the base station identifies the terminal device based on the S-TMSI;

[0011] Step S3: Since the S-TMSI is unique within the MME Group, this design can reduce the use of permanent identifiers and enhance security. The base station uses the S-TMSI to match the terminal and search for the user context.

[0012] Step S4: After the base station matches the S-TMSI terminal, the base station sends an eNB CP Relocation Indication message and carries the UL CP Security Information field for verifying security with the help of the core network;

[0013] Step S5: If the scenario occurs where the S-TMSI-matched terminal and the core network NAS layer security verification fails, the S-TMSI is used as the first layer screening as the target terminal for restoring the RRC connection;

[0014] Step S6: after verifying the security according to the core network, determine whether the verification is passed; if passed, send a ConnectionEstablishment Indication message and carry the DL CP Security Information field. After receiving the message, the base station sends an RRC Reestablishment message to carry the downlink key to the terminal. The terminal receives the reestablishment message, replies with an RRCReestablishment Complete message, and completes the reestablishment process; if not passed, the Connection EstablishmentIndication message will not carry the DL CP Security Information field, the base station cannot obtain the downlink key, the reestablishment process fails, and the state is changed to RRC idle;

[0015] Step S7: Reconstruct and convert RRC Setup. Through fast state switching and context reuse, this design is used to meet the overall needs of NB-IoT devices and provide key protection for device communication.

[0016] Step S8: After receiving the RRC Setup message, the terminal re-establishes the context, obtains the corresponding terminal configuration, and replies with an RRC Setup Complete message to complete the RRC establishment process;

[0017] Step S9: In NB-IoT, the CP mode does not enable the security mechanism of the AS layer, and its security completely depends on the security mechanism of the NAS layer.

[0018] Preferably, step S5 is used to save network-side resources and has considerable security in conventional scenarios.

[0019] Preferably, step S4 is used to verify security by means of a core network.

[0020] Preferably, in step S7, the RRC Setup is reconstructed and converted, and is used to optimize latency, power consumption, and reliability through fast state switching and context multiplexing.

[0021] The technical effects of the method for CP mode reconstruction optimization for the Internet of Things of the present invention are as follows:

[0022] 1. In the present invention, after the reestablishment fails and the connection state is restored by RRC Setup, the security verification of the NAS layer can be restarted through uplink and downlink NAS messages to ensure the integrity and security of the communication.

[0023] 2. In the present invention, after the terminal completes the RRC connection, it reconnects with the core network, completes authentication through up and down NAS messages, and completes the restart of the security mode, thus achieving the same security purpose as the normal reconstruction process. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] Figure 1 This is a flowchart of the CP mode reconstruction optimization of the present invention.

[0025] Figure 2 This is a flow chart of the reconstruction optimization strategy of the present invention. DETAILED DESCRIPTION

[0026] The embodiments of the present invention are described in detail below with reference to the accompanying drawings.

[0027] The specific implementation modes of the present invention are described below so that those skilled in the art can understand the present invention. However, it should be clear that the present invention is not limited to the scope of the specific implementation modes. For those of ordinary skill in the art, as long as various changes are within the spirit and scope of the present invention as defined and determined by the attached claims, these changes are obvious, and all inventions and creations utilizing the concept of the present invention are protected.

[0028] A method for CP mode reconstruction optimization for the Internet of Things, comprising the following steps:

[0029] Step S1: The terminal initiates the reestablishment process and sends an RRC Reestablishment Request message to the base station;

[0030] Step S2: After receiving the RRC Reestablishment Request message, the base station identifies the terminal device based on the S-TMSI;

[0031] Step S3: Since the S-TMSI is unique within the MME Group, this design can reduce the use of permanent identifiers and enhance security. The base station uses the S-TMSI to match the terminal and search for the user context.

[0032] Step S4: After the base station matches the S-TMSI terminal, the base station sends an eNB CP Relocation Indication message and carries the UL CP Security Information field for verifying security with the help of the core network;

[0033] Step S5: If the S-TMSI-matched terminal and the core network NAS layer security verification fails, the S-TMSI is used as the first layer screening as the target terminal for restoring the RRC connection;

[0034] Step S6: after verifying the security according to the core network, determine whether the verification is passed; if passed, send a ConnectionEstablishment Indication message and carry the DL CP Security Information field. After receiving the message, the base station sends an RRC Reestablishment message to carry the downlink key to the terminal. The terminal receives the reestablishment message, replies with an RRCReestablishment Complete message, and completes the reestablishment process; if not passed, the Connection EstablishmentIndication message will not carry the DL CP Security Information field, the base station cannot obtain the downlink key, the reestablishment process fails, and the state is changed to RRC idle;

[0035] Step S7: Reconstruct and convert RRC Setup. Through fast state switching and context reuse, this design is used to meet the overall needs of NB-IoT devices and provide key protection for device communication.

[0036] Step S8: After receiving the RRC Setup message, the terminal re-establishes the context, obtains the corresponding terminal configuration, and replies with an RRC Setup Complete message to complete the RRC establishment process;

[0037] Step S9: In NB-IoT, the CP mode does not enable the security mechanism of the AS layer, and its security completely depends on the security mechanism of the NAS layer.

[0038] Step S5 of this implementation scheme is used to save network-side resources and has considerable security in conventional scenarios.

[0039] Step S4 of this embodiment is used to verify security with the help of the core network.

[0040] In step S7 of this implementation scheme, RRC Setup is rebuilt and converted to optimize latency, power consumption, and reliability through fast state switching and context multiplexing.

[0041] When this implementation plan is implemented,

[0042] 1. In wireless communication, due to abnormal reasons such as radio link failure and configuration failure, the terminal will initiate a re-establishment process. At this time, the terminal will send an RRC Reestablishment Request message to the base station. After receiving the request message, the base station relies on S-TMSI to identify the terminal device, and S-TMSI is unique within the MME Group. This design can not only reduce the use of permanent identifiers, but also enhance security. Using this feature, the base station uses S-TMSI to match the terminal to find the user context. In the future, if the security verification of the terminal and the core network NAS layer fails, S-TMSI can also be used as the first layer of screening as the target terminal for restoring the RRC connection. This can save network-side resources and has considerable security in normal scenarios.

[0043] 2. After matching the S-TMSI, the base station will send an eNB CP Relocation Indication message and carry the ULCP Security Information field (NAS layer security key brought by the terminal) to verify security with the help of the core network. After the core network verifies the uplink security key, it determines whether the verification is successful:

[0044] (a) If the verification is successful, the base station sends a Connection Establishment Indication message with the DLCP Security Information field. After receiving the message, the base station sends an RRC Reestablishment message with the downlink key to the terminal. The terminal receives the reestablishment message, replies with an RRC Reestablishment Complete message, and completes the reestablishment process.

[0045] (b) If the verification fails, the Connection Establishment Indication message will not carry the DLCP Security Information field, the base station cannot obtain the downlink key, the reestablishment process fails, and the state changes to the RRC idle state.

[0046] The optimization of the present invention is that in the case of verification failure, the RRC Reestablishment message can be converted into an RRC Setup message, carrying the establishment information of the minimum configuration requirements and requiring the terminal to restore to the connected state. Such optimization can:

[0047] 1) Reduce the delay required for RRC connection recovery

[0048] 2) If the UE needs to fall back to the idle state after the reestablishment fails, repeated reestablishment attempts are required to go through a complete random access process to initiate the RRC connection again, which consumes a lot of time. By directly converting the RRC Setup process and skipping some redundant steps, the time to restore the connection state is greatly shortened.

[0049] 3) Reduce signaling overhead and device power consumption

[0050] 4) Simplify repeated signaling, shorten the activation time of the terminal RF module, and reduce frequent state switching energy consumption and extend battery life (especially important for low-power devices such as NB-IoT).

[0051] 5) Improve network reliability and enhance user experience

[0052] 6) Fast fault tolerance mechanism: when the reconstruction fails, the RRC Setup is immediately converted to avoid continuous service interruption caused by repeated reconstruction. In weak coverage or high interference scenarios, diversified connection strategies are used Improve the final access success rate and increase the robustness of the communication system.

[0053] 7) Optimize resource utilization

[0054] 8) Reduce air interface resource competition, avoid a large number of UEs initiating random access at the same time after returning to the idle state due to reconstruction failure, reduce the probability of PRACH channel conflict, optimize resource utilization, and improve the overall throughput of the base station.

[0055] 3. Reconstruct the conversion RRC Setup, and optimize latency, power consumption, reliability, etc. through fast state switching and context reuse. This design meets the overall needs of NB-IoT devices and provides key guarantees for device communication.

[0056] 4. After receiving the RRC Setup message, the terminal re-establishes the context, obtains the corresponding terminal configuration, and replies with an RRC Setup Complete message to complete the RRC establishment process.

[0057] 5. In NB-IoT, the CP mode does not enable the security mechanism of the AS layer, and its security is completely dependent on the security mechanism of the NAS layer (such as NAS-COUNT and NAS-MAC). The benefits of this include reducing the processing burden of the AS layer, but there may be some compromises in latency or security. This design has unique advantages in resource-constrained IoT scenarios:

[0058] 1) Avoid double security overhead:

[0059] 2) In CP mode, there is no need to maintain the security context of the AS layer and the NAS layer at the same time, which eliminates the encryption / decryption operation of the AS layer, reduces security-related processing time, and reduces the computing burden of the device.

[0060] 3) Simplify the signaling process.

[0061] 4) Reduce key negotiation steps. AS layer security requires independent key derivation, while CP mode can directly reuse the existing security context of the NAS layer, avoiding the signaling overhead caused by the AS layer key exchange. In the reconstruction process, there is no need to reactivate AS layer security or update AS layer keys. The legitimacy of the message can be verified by relying on NAS-COUNT and NAS-MAC of the NAS layer, shortening the recovery time.

[0062] 5) Reduce the transmission requirements for security verification.

[0063] 6) The message authentication code of the NAS layer security mechanism is shorter and more suitable for narrowband channels and repeated transmission mechanisms than the key of the AS layer integrity protection.

[0064] 7) NB-IoT devices are usually stationary or have low mobility, and the NAS layer security is sufficient to prevent replay attacks and tampering. The NAS layer security is directly managed by the core network (MME), avoiding the resource transmission overhead of the base station on the key.

[0065] 8) In the design of the present invention, after the reestablishment fails and the connection state is restored through RRC Setup, the security verification of the NAS layer can be restarted through uplink and downlink NAS messages to ensure the integrity and security of the communication.

[0066] 9) After the terminal completes the RRC connection, it reconnects with the core network, completes authentication through uplink and downlink NAS messages, and completes the restart of the security mode, thus achieving the same security purpose as the normal reconnection process.

Claims

1. A method for CP mode reconstruction optimization for the Internet of Things, characterized in that: The following steps are involved: Step S1: The terminal initiates the reestablishment process and sends an RRC Reestablishment Request message to the base station; Step S2: After receiving the RRC Reestablishment Request message, the base station identifies the terminal device based on the S-TMSI; Step S3: Since the S-TMSI is unique within the MME Group, this design can reduce the use of permanent identifiers and enhance security. The base station uses the S-TMSI to match the terminal and search for the user context. Step S4: After the base station matches the S-TMSI terminal, the base station sends an eNB CP Relocation Indication message and carries the UL CP Security Information field for verifying security with the help of the core network; Step S5: If the scenario occurs where the S-TMSI-matched terminal and the core network NAS layer security verification fails, the S-TMSI is used as the first layer screening as the target terminal for restoring the RRC connection; Step S6: after verifying the security according to the core network, determine whether the verification is passed; if passed, send a ConnectionEstablishment Indication message and carry the DL CP Security Information field. After receiving the message, the base station sends an RRC Reestablishment message to carry the downlink key to the terminal. The terminal receives the reestablishment message, replies with an RRCReestablishment Complete message, and completes the reestablishment process; if not passed, the Connection EstablishmentIndication message will not carry the DL CP Security Information field, the base station cannot obtain the downlink key, the reestablishment process fails, and the state is changed to RRC idle; Step S7: Reconstruct and convert RRC Setup. Through fast state switching and context reuse, this design is used to meet the overall needs of NB-IoT devices and provide key protection for device communication. Step S8: After receiving the RRC Setup message, the terminal re-establishes the context, obtains the corresponding terminal configuration, and replies with an RRC Setup Complete message to complete the RRC establishment process; Step S9: In NB-IoT, the CP mode does not enable the security mechanism of the AS layer, and its security completely depends on the security mechanism of the NAS layer.

2. The method for CP mode reconstruction optimization for the Internet of Things according to claim 1, characterized in that: The step S5 is used to save network resources and has considerable security in conventional scenarios.

3. The method for CP mode reconstruction optimization for the Internet of Things according to claim 1, characterized in that: The step S4 is used to verify security with the help of the core network.

4. The method for CP mode reconstruction optimization for the Internet of Things according to claim 1, characterized in that: In step S7, the RRC Setup is rebuilt and converted to optimize latency, power consumption, and reliability through fast state switching and context multiplexing.