AMF Encryption for 5G Core Network Privacy Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G networks, user information leakage occurs when user equipment (UE) accesses the core network, as interaction information between network function (NF) entities directly carries user data, potentially leading to privacy breaches, especially when NF entities are deployed on edge clouds with limited security and unattended operations.

Innovation Solution

Implementing a communication method where user information is encrypted before being carried in interaction information between NF entities, such as the Access Control and Mobility Management Function (AMF), Session Management Function (SMF), User Data Management (UDM), Policy Control Function (PCF), and Charging Function (CHF), ensuring that only encrypted user information is transmitted, and decryption occurs only when necessary for authorized entities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If user information is directly carried in interaction information between NF entities, then information transmission efficiency is improved, but user privacy security deteriorates

Engineering Contradiction:
Improveinformation transmission efficiencyVSAvoiduser privacy leakage risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary encryption mechanism between the AMF and other NF entities. The AMF encrypts user information before transmitting it to other network functions, and decryption is performed only when the receiving entity needs to access the information. This intermediary encryption layer prevents direct exposure of user data while maintaining the flow of information between entities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the state of user information from plaintext to encrypted form during transmission between NF entities. The information is encrypted using encryption keys managed by the AMF, transforming the data into a secure parameter state that can only be decrypted by authorized entities, thus preventing privacy leakage while maintaining transmission efficiency.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If user information is encrypted in interaction information, then user privacy security is improved, but device complexity increases

Engineering Contradiction:
Improveuser privacy leakage riskVSAvoidencryption and decryption processing
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The AMF performs the encryption and decryption operations autonomously using keys that are already established during the authentication process. The AMF encrypts user information when sending it to other NF entities and automatically decrypts it when receiving information, without requiring external intervention or complex key management systems. This self-service approach reduces overall system complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The encryption keys are preliminarily established during the authentication process between the UE and the AMF. Once these keys are in place, the AMF can directly use them for encrypting and decrypting user information in subsequent communications, eliminating the need for complex key exchange mechanisms during data transmission and reducing processing complexity.

Inventive Principle:
Principle #10Preliminary action

3Speed

If NF entities are deployed on edge clouds, then network flexibility and latency are improved, but security control capability deteriorates

Engineering Contradiction:
Improvedata transmission latencyVSAvoidsecurity control capability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The AMF acts as a trusted intermediary between edge cloud NF entities and the core network. It encrypts user information before it reaches edge cloud entities and maintains security control through centralized key management. This intermediary role allows edge cloud deployment for low latency while preserving security control capability through the AMF's encryption mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies encryption parameter changes to data transmitted between edge cloud NF entities and the core network. By transforming user information into encrypted form during transmission to and from edge clouds, the system maintains the security control capability even when NF entities are deployed on less secure edge cloud platforms, thus enabling both low latency and security.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11570617B2Communication method and communications apparatus
Publication Date: 2023.01.31 HUAWEI TECH CO LTD
  • US11570617B2 patent drawing
  • US11570617B2 patent drawing
  • US11570617B2 patent drawing

AI summary

A communication method and a communications apparatus are provided. The method includes: when receiving a first PDU session establishment request sent by a UE, encrypting, by an access and management network element (AMF), user information in the request, to obtain encrypted user information; and sending, by the AMF, a second PDU session establishment request to an SMF in response to the first PDU session establishment request, where the second PDU session establishment request carries the encrypted user information. In this manner, after the UE accesses a core network, an AMF entity may encrypt user information of the UE. The interaction information between NF entities, for example, the AMF entity and an SMF entity, carries the encrypted user information, which helps prevent user privacy leakage.