5G UE Security Context Management Across 3GPP And Non-3GPP Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing 5G communication systems face challenges in managing security contexts for user equipment (UE) across both 3GPP and non-3GPP accesses, requiring effective methods to ensure secure communication and registration to the same public land mobile network (PLMN).

Innovation Solution

A method and apparatus for performing security mode control procedures involving first and second authentication procedures and key agreement processes over 3GPP and non-3GPP accesses, using a key set identifier (ngKSI) to establish and manage security contexts, ensuring registration to the same AMF and PLMN across both access types.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate authentication procedures are performed for 3GPP and non-3GPP accesses, then security is enhanced for each access type, but device complexity and procedure overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidprocedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines separate authentication procedures for 3GPP and non-3GPP accesses into a unified authentication framework. The UE performs authentication with the AMF that validates credentials for both access types simultaneously, reducing procedural complexity while maintaining security. The security context established through this unified procedure can be reused across both access types, eliminating the need for separate authentication processes.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements a universal security context that serves multiple access types (both 3GPP and non-3GPP) through a single authentication procedure. The established security context is multi-functional, enabling secure communication across different access types without requiring separate authentication mechanisms, thereby reducing device complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate security contexts are maintained for 3GPP and non-3GPP accesses, then security isolation is improved, but information management complexity increases

Engineering Contradiction:
Improvesecurity isolationVSAvoidinformation management overhead
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent merges the management of security contexts for 3GPP and non-3GPP accesses into a unified security context structure. Instead of maintaining separate security contexts that would require complex tracking and synchronization, the system uses a single security context that can be applied to both access types, significantly reducing information management overhead while preserving security integrity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal security context that functions across both 3GPP and non-3GPP access types. This single security context contains all necessary security parameters and credentials that can be reused regardless of access type, eliminating the need for separate security context management and reducing the complexity of tracking and synchronizing multiple security states.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If multiple authentication procedures are performed sequentially, then security verification is thorough, but communication establishment time increases

Engineering Contradiction:
Improvesecurity verificationVSAvoidcommunication establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs authentication and security context establishment as a preliminary action that precedes actual data transmission. By completing the authentication procedure once and establishing a reusable security context before communication begins, the system ensures thorough security verification without requiring repeated authentication exchanges during subsequent communications, thereby reducing overall establishment time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent combines multiple authentication procedures into a single unified authentication process that verifies credentials for both 3GPP and non-3GPP accesses simultaneously. This merged authentication procedure maintains thorough security verification by checking all necessary credentials in one process rather than executing separate authentication sequences, significantly reducing the time required for communication establishment.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3785460B1Security protection method and apparatus in wireless communication system
Publication Date: 2025.08.27 SAMSUNG ELECTRONICS CO LTD
  • EP3785460B1 patent drawingFigure 1
  • EP3785460B1 patent drawingFigure 2
  • EP3785460B1 patent drawingFigure 3

AI summary

A method of performing a security mode control procedure by a user equipment (UE), and an apparatus therefor are disclosed. The method includes performing, over a 3 rd generation partnership project (3GPP) access, a first authentication procedure and a first key agreement procedure with an access and mobility management function (AMF), wherein a key set identifier (ngKSI) is changed during the first authentication procedure and the first key agreement procedure, receiving, from the AMF over the 3GPP access, a first security mode command message including the ngKSI, and receiving, from the AMF over a non-3GPP access, a second security mode command message including the ngKSI, wherein the UE is registered to the AMF and a same public land mobile network (PLMN) over both the 3GPP access and the non-3GPP access.