5G UE Registration Security Capability Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the 5G communication system, the separation of Access and Mobility Management Function (AMF) and Session Management Function (SMF) leads to security-related vulnerabilities due to communication at a level lower than the security capabilities of User Equipment (UE) and network nodes, necessitating a method to handle security information efficiently.

Innovation Solution

A method where the UE transmits a registration request message with security-related capability information to the network node, receives and verifies authentication requests, and responds with security mode messages to ensure secure communication aligned with both parties' capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security-related information is transmitted between UE and network node, then communication security is improved, but security vulnerabilities arise due to communication at a level lower than security capabilities

Engineering Contradiction:
Improvecommunication securityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by having the UE include security capability information in the registration request message before actual data transmission. The network node verifies these capabilities in advance during the registration phase, ensuring that subsequent communications occur at an appropriate security level matching both parties' capabilities, thereby preventing security vulnerabilities before they can manifest.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security capability verification is performed, then security reliability is improved, but communication complexity increases

Engineering Contradiction:
Improvesecurity capability verificationVSAvoidcommunication procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges security capability verification with the existing registration procedure. By combining these functions, the verification process leverages the established registration message flow and handling procedures, avoiding the need for separate verification protocols. This integration reduces overall communication complexity while maintaining security reliability.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If security mode command messages are transmitted, then secure communication is established, but message transmission overhead increases

Engineering Contradiction:
Improvesecure communication establishmentVSAvoidmessage transmission overhead
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent uses preliminary action by establishing security modes during the registration phase through the security mode command message. By setting up the security configuration in advance before actual data transmission begins, the system avoids repeated security negotiation overhead during subsequent communications, thereby reducing overall message transmission overhead while ensuring secure communication is established.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11546759B2Method and device for communicating in wireless communication system
Publication Date: 2023.01.03 SAMSUNG ELECTRONICS CO LTD
  • US11546759B2 patent drawing
  • US11546759B2 patent drawing
  • US11546759B2 patent drawing

AI summary

The present disclosure relates to a 5G or pre-5G communication system for supporting a higher data transfer rate beyond a 4G communication system such as LTE. A terminal according to an embodiment of the present disclosure performs the operations of: transmitting a registration request message to a network node; receiving an authentication request message containing information on a security related capability from the network node; verifying the security related capability by using the authentication request message; transmitting a first message as a response to the authentication request message; receiving a security mode command message from the network node; and transmitting, to the network node, a security mode completion message as a response to the security mode command message, wherein the information on the security related capability includes information on a capability related to security between the terminal and the network node.