5G Terminal Security via Selective Message Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 5G wireless communication systems, there is a need for enhanced information security mechanisms to protect data transmission between terminals and networks, particularly in scenarios where mobility management and session management entities are separated, requiring secure communication with adequate corresponding nodes.
Innovation Solution
The implementation of an apparatus and method involving a transceiver and processor in terminals and access and mobility management functions (AMFs) that transmit and receive registration and service request messages with primary and secondary information, where primary information is plain and secondary information is encrypted, to ensure secure information exchange and node discovery.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all information is encrypted in registration and service request messages, then information security is improved, but processing complexity and overhead increase
Solution Approach 1:
The patent segments information into two categories: information that requires encryption for security and information that should remain unencrypted for efficient processing. The AMF selectively applies encryption only to specific information elements (such as user identity and service data) while leaving other elements (such as mobility management data) in plain text, thereby resolving the contradiction between security and processing complexity.
Solution Approach 2:
The patent applies different security qualities to different parts of the message based on their sensitivity and functional requirements. Critical information elements receive strong encryption protection, while non-critical elements are transmitted without encryption or with lighter protection mechanisms, optimizing the balance between security and processing overhead.
2Reliability
If security procedures are applied to all communication messages, then information security is improved, but communication efficiency deteriorates
Solution Approach 1:
The patent segments communication messages into different types based on their security requirements. Registration requests, service requests, and other message types are analyzed to determine which information elements require security procedures. This selective approach maintains security for sensitive data while improving communication efficiency by avoiding unnecessary encryption overhead for non-sensitive data.
Solution Approach 2:
The patent applies security procedures partially rather than universally. Instead of encrypting all information in all messages, the system applies encryption only to the specific information elements that require protection in specific message types, thereby maintaining adequate security while minimizing the impact on communication efficiency.
3Adaptability or versatility
If mobility management and session management are handled by separate entities, then system flexibility is improved, but node discovery complexity increases
Solution Approach 1:
The patent introduces the AMF as an intermediary entity that facilitates communication between the UE and the appropriate network functions. The AMF receives registration and service request messages from the UE, determines the appropriate target node based on the message content and security requirements, and forwards the message accordingly. This intermediary approach maintains system flexibility while managing node discovery complexity centrally at the AMF.
Solution Approach 2:
The patent implements feedback mechanisms where the AMF receives information from the UE about its capabilities, current state, and service requirements. Based on this feedback, the AMF makes intelligent decisions about which network function to contact and what security measures to apply, thereby simplifying the node discovery process while maintaining system flexibility.
Data Source
AI summary
The present disclosure relates to a pre-5th-Generation (5G) or 5G communication system to be provided for supporting higher data rates Beyond 4th-Generation (4G) communication system such as Long Term Evolution (LTE). According to various embodiments of the present disclosure, an apparatus of a terminal in a wireless communication system may include a transceiver and at least one processor coupled to the transceiver, wherein the at least one processor may be configured to transmit a registration request message or a service request message including primary information and secondary information to an access and mobility management function (AMF), the primary information may be plain information, and the secondary information may be encrypted information.


