AMF Security Context Activation for Simultaneous NAS Connections

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G systems, there is a challenge in activating a new security context for simultaneous NAS connections without disrupting ongoing services, as existing methods either require unnecessary overhead or suspend NAS signalling, leading to service disruptions.

Innovation Solution

A method that allows the activation of a new security context over simultaneous NAS connections by retaining the old security context using a timer or an intermediary state until the new context is active on both connections, minimizing disruption and optimizing signalling overhead.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a new security context is activated for simultaneous NAS connections, then security is improved, but service disruption occurs due to suspension of NAS signalling

Engineering Contradiction:
ImprovesecurityVSAvoidservice continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces an intermediary state before fully activating the new security context, allowing preliminary setup and verification without disrupting ongoing services. This preliminary action enables the system to prepare the new security context while maintaining the old one active, thus avoiding service disruption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs an intermediary state as a mediator between the old and new security contexts. This intermediary state allows the system to transition from the old security context to the new one without direct disruption, acting as a buffer that maintains service continuity during the security context change.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a new security context is activated for simultaneous NAS connections, then security is improved, but signalling overhead increases

Engineering Contradiction:
ImprovesecurityVSAvoidsignalling overhead
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent applies partial action by introducing an intermediary state that is neither the old nor the full new security context state. This partial state reduces the signalling overhead required for complete security context activation while still achieving the security improvement goal through staged transitions.

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If the old security context is retained during activation of new context, then service continuity is maintained, but security vulnerability increases

Engineering Contradiction:
Improveservice continuityVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The intermediary state acts as a secure mediator that manages the transition between old and new security contexts. It controls when the old context is deactivated and ensures the new context is properly activated, thereby maintaining service continuity while minimizing security vulnerability through controlled transitions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements feedback mechanisms to monitor the activation status of the new security context. This feedback allows the system to determine when it is safe to deactivate the old security context, ensuring that service continuity is maintained only when the new context is fully operational and secure.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12137340B2First and second connections with an authentication management function
Publication Date: 2024.11.05 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US12137340B2 patent drawing
  • US12137340B2 patent drawing
  • US12137340B2 patent drawing

AI summary

In some embodiments, a method in a wireless device comprises registering first and second connections with an AMF. The first and second connections share a first security context and connect via first and second access networks, respectively. The method further comprises establishing a second security context with the AMF, setting a flag to a first value based on the second security context having been taken into use on the first connection, and setting the flag to a second value based on the second security context having been taken into use on the second connection. The second value indicates that the second security context has been taken into use on both the first and second connections. The method further comprises retaining the first security context when the flag is set to the first value, and disposing of the first security context after setting the flag to the second value.