5G Security Algorithm Negotiation via RRC and PDU Separation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless communication networks, particularly in 5G architecture, the separation of UE registration and user plane establishment procedures complicates the negotiation of security and integrity algorithms, leading to increased message overhead and reduced flexibility in managing user plane security policies compared to 4G networks.

Innovation Solution

The system and method for negotiating security and integrity algorithms involve a base station transmitting a security command message to a user equipment (UE) with indications of integrity and encryption algorithms, triggering a radio resource control (RRC) traffic signaling protection procedure, which includes negotiating RRC and user plane security activations. This process is separate for control plane and user plane traffic, allowing for flexible security policy management and reduced message overhead.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If security and integrity algorithms are negotiated separately for control plane and user plane traffic, then flexibility in managing user plane security policies is improved, but device complexity and message overhead increase

Engineering Contradiction:
Improveflexibility in managing user plane security policiesVSAvoidcomplexity of security negotiation procedures
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the security negotiation process into two distinct phases: control plane security negotiation (RRC signaling protection) and user plane security negotiation (PDU session establishment). This segmentation allows each plane to have independent security algorithm selection and activation, providing flexibility in managing user plane security policies while maintaining clear procedural boundaries to manage complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic security algorithm selection where the UE and base station can negotiate different integrity and encryption algorithms for control plane versus user plane traffic. The security algorithms are not fixed but can be dynamically selected and activated based on specific traffic requirements, enabling adaptive security management.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If security algorithms are negotiated during separate procedures, then flexibility in security policy management is improved, but message overhead increases

Engineering Contradiction:
Improvesecurity policy management flexibilityVSAvoidmessage overhead
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent merges multiple security negotiation elements into consolidated message exchanges. The security command message and security command complete message carry multiple algorithm indications and activation commands simultaneously, reducing the number of separate messages needed while maintaining the flexibility of separate control plane and user plane security management.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If RRC traffic signaling protection and PDU session establishment are performed in sequence, then security activation is more controlled, but establishment time increases

Engineering Contradiction:
Improvesecurity activation controlVSAvoidPDU session establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary security algorithm negotiation during the RRC traffic signaling protection phase before PDU session establishment. By pre-negotiating and activating control plane security algorithms, the system ensures that security is already in place and verified before user plane data transmission begins, improving reliability while allowing parallel processing to minimize time loss.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11895498B2Method and device for negotiating security and integrity algorithms
Publication Date: 2024.02.06 FUTUREWEI TECHNOLOGIES INC
  • US11895498B2 patent drawing
  • US11895498B2 patent drawing
  • US11895498B2 patent drawing

AI summary

Embodiments of this disclosure provide techniques for communicating in a wireless communication system. In particular, a user equipment (UE) may receiving a security command message from a base station comprising an indication of an integrity protection algorithm and an indication of an encryption algorithm. The first security command message may trigger a radio resource control (RRC) traffic signaling protection procedure between the UE and the base station. The UE transmits a security command complete message to the base station. The security command complete message may trigger a packet data unit (PDU) session establishment procedure to establish a PDU session between the UE and the base station.