5G Security Association Failure Handling Via IKE Error Payloads
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods do not address how to handle security association establishment failures when user equipment attempts to connect to a 5G core network via untrusted non-3GPP access networks, leading to incomplete or unsuccessful network connections.
Innovation Solution
Implement an interworking function node and Access and Mobility Management function to manage network connections, generating response messages indicating connection failures over untrusted access networks, and utilizing IKE response messages with error payloads to handle authentication and secure connection establishment rejections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If security association establishment is attempted over untrusted non-3GPP access networks, then network connectivity is enabled, but authentication failures occur without proper error handling
Solution Approach 1:
The patent implements feedback mechanisms where the network sends specific error codes (e.g., 5GMM cause values) to the UE when security association establishment fails. This feedback enables the UE to understand the failure reason and take appropriate actions such as retrying with updated parameters or switching to alternative networks, thereby improving connection establishment reliability while maintaining network access capability.
Solution Approach 2:
The patent establishes preliminary error handling frameworks and message structures (such as predefined error codes and response message formats) before authentication failures occur. This preliminary preparation ensures that when security association establishment fails, the system can immediately provide structured error information and guidance, preventing incomplete connections and improving reliability.
2Reliability
If authentication failure is rejected without detailed error information, then security is maintained, but troubleshooting and recovery are difficult
Solution Approach 1:
The patent applies local quality by providing different levels of error information based on the specific failure context. Rather than uniformly revealing all security details or providing generic error messages, the system sends targeted error codes (such as 5GMM cause values) that provide sufficient information for recovery without compromising overall security. This enables easy troubleshooting and recovery while maintaining security assurance.
3Reliability
If comprehensive error handling messages are implemented, then connection recovery is improved, but message complexity increases
Solution Approach 1:
The patent manages message complexity by changing parameters such as using standardized error code formats (5GMM cause values) and structured response message templates. These parameter changes allow comprehensive error information to be conveyed through predefined, compact message structures rather than complex custom protocols, improving connection recovery capability while controlling message structure complexity.
Data Source
AI summary
An interworking function in a core network system, such as a 5G core network, attempts to establish a secure association with user equipment (UE) in an untrusted access network. When the secure association is not accepted by the 5G core network, the UE receives from the core network a response including a message type indicating that Non-3GPP access to the 5G core network is not allowed. Upon receiving the response message, the UE ends the session by sending a 5G-Stop message formatted in an Extensible Authentication Protocol (EAP) response. The EAP-Response/5G-Stop message includes a message-id field with a 5G Stop value.


