5G Security Algorithm Negotiation via RRC and PDU Separation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In wireless communication networks, particularly in 5G architecture, the separation of UE registration and user plane establishment procedures complicates the negotiation of security and integrity algorithms, leading to increased message overhead and reduced flexibility in managing user plane security policies compared to 4G networks.
Innovation Solution
The system and method for negotiating security and integrity algorithms involve a base station transmitting a security command message to a user equipment (UE) with indications of integrity and encryption algorithms, triggering a radio resource control (RRC) traffic signaling protection procedure, which includes negotiating RRC and user plane security activations. This process is separate for control plane and user plane traffic, allowing for flexible security policy management and reduced message overhead.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If security and integrity algorithms are negotiated separately for control plane and user plane traffic, then flexibility in managing user plane security policies is improved, but device complexity and message overhead increase
Solution Approach 1:
The patent segments the security negotiation process into two distinct phases: control plane security negotiation (RRC signaling protection) and user plane security negotiation (PDU session establishment). This segmentation allows each plane to have independent security algorithm selection and activation, providing flexibility in managing user plane security policies while maintaining clear procedural boundaries to manage complexity.
Solution Approach 2:
The patent implements dynamic security algorithm selection where the UE and base station can negotiate different integrity and encryption algorithms for control plane versus user plane traffic. The security algorithms are not fixed but can be dynamically selected and activated based on specific traffic requirements, enabling adaptive security management.
2Adaptability or versatility
If security algorithms are negotiated during separate procedures, then flexibility in security policy management is improved, but message overhead increases
Solution Approach 1:
The patent merges multiple security negotiation elements into consolidated message exchanges. The security command message and security command complete message carry multiple algorithm indications and activation commands simultaneously, reducing the number of separate messages needed while maintaining the flexibility of separate control plane and user plane security management.
3Reliability
If RRC traffic signaling protection and PDU session establishment are performed in sequence, then security activation is more controlled, but establishment time increases
Solution Approach 1:
The patent performs preliminary security algorithm negotiation during the RRC traffic signaling protection phase before PDU session establishment. By pre-negotiating and activating control plane security algorithms, the system ensures that security is already in place and verified before user plane data transmission begins, improving reliability while allowing parallel processing to minimize time loss.
Data Source
AI summary
Embodiments of this disclosure provide techniques for communicating in a wireless communication system. In particular, a user equipment (UE) may receiving a security command message from a base station comprising an indication of an integrity protection algorithm and an indication of an encryption algorithm. The first security command message may trigger a radio resource control (RRC) traffic signaling protection procedure between the UE and the base station. The UE transmits a security command complete message to the base station. The security command complete message may trigger a packet data unit (PDU) session establishment procedure to establish a PDU session between the UE and the base station.


