5G NR RAN Multicast Security by Downlink Tunnel Identity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a lack of clarity in how radio access networks apply security protection to multicast and broadcast service data packets in 5G NR systems, particularly in scenarios involving multiple UEs receiving the same data packets.
Innovation Solution
A method for managing security protection in radio access networks and user equipment by determining the appropriate security check scheme and protection based on the identity of the downlink tunnel and configuration, allowing for null or non-null security checks and protections to be applied selectively to multicast and broadcast data packets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security protection is applied to all multicast and broadcast service data packets, then data integrity and confidentiality are improved, but system complexity and processing overhead increase
Solution Approach 1:
The patent applies different security protection treatments to different data packets based on their type. MBS data packets receive either null security protection or UE-specific security protection, while non-MBS data packets receive common security protection. This localized differentiation reduces overall system complexity while maintaining necessary security for each data type.
Solution Approach 2:
The patent segments security protection into multiple levels: null security protection for certain MBS packets, UE-specific security protection for other MBS packets, and common security protection for non-MBS packets. This segmentation allows the system to apply appropriate security measures only where needed, reducing unnecessary processing overhead.
2Reliability
If UE-specific security protection is applied to MBS data packets, then data confidentiality is improved, but processing overhead and complexity increase
Solution Approach 1:
The patent applies UE-specific security protection only to certain MBS data packets that require enhanced confidentiality, rather than to all MBS packets. For other MBS packets, null security protection is sufficient. This partial application of security measures maintains confidentiality where needed while avoiding unnecessary processing overhead.
Solution Approach 2:
The patent changes the security protection parameter dynamically based on the data packet type and UE configuration. The gNB determines whether to apply null security protection, UE-specific security protection, or common security protection by evaluating packet characteristics and UE capabilities, thereby optimizing processing efficiency while maintaining security.
3Ease of manufacture
If common security protection is applied to all data packets, then implementation simplicity is improved, but security effectiveness for individual UEs deteriorates
Solution Approach 1:
The patent implements common security protection as the baseline for all data packets, providing a simple unified approach. However, it locally enhances security for MBS data packets by applying UE-specific security protection when needed, thereby maintaining both implementation simplicity and security effectiveness.
Data Source
AI summary
A radio access network (RAN) can perform a method for managing security protection for multicast and/or broadcast services (MBS). The method includes receiving (802), from a core network (CN) via a DL tunnel, a data packet associated with an MBS session; prior to transmitting the data packet to a plurality of UEs, determining (804) which security protection to apply to the data packet based on an identity of the DL tunnel; and transmitting (806) the data packet to the plurality of UEs using the determined security protection. A UE can receive (902), from a RAN, a configuration for establishing a logical channel with the RAN; receive (904), from the RAN via the logical channel, a data packet associated with an MBS session; determine (906) which security protection to apply to the data packet based on the configuration; and apply (908) the determined security protection to the data packet.


