5G Wireless Access Control With Hashed Temporary S-NSSAIs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication systems lack robust security measures for secure access control in next-generation radio access networks, particularly in 5G new radio systems, which are vulnerable to unauthorized access and data breaches.
Innovation Solution
Implementing secure access control mechanisms in 5G new radio systems using closed access group (CAG) identifiers, radio resource control (RRC) based access control, non-access stratum (NAS) based access control, and hashed temporary S-NSSAIs during access stratum connection establishment to enhance security and authorization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional access control methods are used in wireless communication systems, then the system structure remains simple and easy to operate, but the system becomes vulnerable to unauthorized access and security breaches
Solution Approach 1:
The patent segments access control into multiple hierarchical layers: Closed Access Group (CAG) identifiers for cell-level access control, RRC-based access control for connection management, and NAS-based access control for session management. Each layer handles specific security functions independently, improving overall security while maintaining manageable complexity through functional separation.
Solution Approach 2:
The patent introduces temporary S-NSSAIs as intermediary identifiers that mask permanent S-NSSAIs during access stratum connections. This intermediary mechanism protects sensitive network slice information while enabling secure access control, resolving the contradiction between security requirements and system complexity.
2Reliability
If hashed temporary S-NSSAIs are used during access stratum connection establishment, then security and privacy protection is improved, but the processing complexity and computational overhead increases
Solution Approach 1:
The patent performs hashing of S-NSSAIs in advance to generate temporary identifiers before actual data transmission occurs. This preliminary processing ensures that permanent S-NSSAIs are never exposed in clear text during access stratum connections, providing privacy protection while allowing the network to maintain efficient processing through pre-computed temporary identifiers.
Data Source
AI summary
Method and apparatus for secure access control in wireless communications are disclosed. In an example, a method includes receiving a broadcast message including system information, identifying a first set of hashed identifiers (IDs) and a first random number based on the system information, and each ID of the first set of hashed IDs is individually hashed using at least the first random number. The method also includes calculating a first hash value for each ID of a second set of IDs using at least the first random number, determining whether at least a hashed ID of the second set of IDs matches a hashed ID of the first set of hashed IDs, and sending a request message based on a determination that at least a hashed ID of the second set of IDs matches a hashed ID of the first set of hashed IDs.


