AMF Controlled Handling of 5G Security Policy for User Plane Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G systems, the lack of a mechanism to handle the Max Data Radio Bearer Integrity Protection (DRB-IP) rate leads to potential rejection of PDU sessions and service delays due to incorrect security policy assignments that exceed the available capacity of user equipment (UE), resulting in inefficient use of radio resources.

Innovation Solution

Implementing a centralized handling mechanism by the Access and Mobility Management Function (AMF) to track and manage the Max DRB-IP rate for each UE, ensuring capacity prior to resource allocation, and dynamically adjusting DRB-IP rates to prevent resource exhaustion and misestimation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the Max DRB-IP rate is not tracked and managed centrally, then the system allows flexible PDU session establishment, but the UE capacity is exceeded leading to session rejection and service delays

Engineering Contradiction:
ImprovePDU session establishment reliabilityVSAvoidService delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The AMF performs preliminary tracking and management of the Max DRB-IP rate before PDU session establishment. By maintaining an up-to-date count of integrity-protected DRBs and their associated rates, the system proactively prevents capacity exhaustion, avoiding session rejections and service delays that would occur without this advance monitoring.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If the Max DRB-IP rate is not dynamically adjusted, then the security policy assignment is simplified, but the radio resources are inefficiently used due to misestimation

Engineering Contradiction:
ImproveRadio resource utilization efficiencyVSAvoidSecurity policy management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The AMF implements a feedback mechanism that continuously monitors the current DRB-IP rate by tracking established PDU sessions and their integrity protection status. This feedback enables dynamic adjustment of security policies to match actual UE capacity utilization, optimizing radio resource efficiency while preventing misestimation of available capacity.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system transitions from static security policy assignment to dynamic adjustment. The AMF adapts the Max DRB-IP rate management based on real-time conditions, adjusting the count of integrity-protected DRBs as sessions are established or released, thereby optimizing resource utilization according to actual system state.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If multiple PDU sessions are established without centralized Max DRB-IP rate handling, then parallel service delivery is enabled, but capacity exhaustion occurs leading to session rejection

Engineering Contradiction:
ImproveParallel PDU session supportVSAvoidSession establishment success rate
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The AMF acts as an intermediary between the SMF and the UE, centralizing the management of Max DRB-IP rate. It receives information about established PDU sessions from SMFs, tracks the cumulative DRB-IP rate, and ensures that the total capacity does not exceed the UE's maximum capability, thereby enabling parallel sessions while preventing capacity exhaustion.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11606682B2AMF controlled handling of the security policy for user plane protection in 5G systems
Publication Date: 2023.03.14 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US11606682B2 patent drawing
  • US11606682B2 patent drawing
  • US11606682B2 patent drawing

AI summary

A method of operating an Access and Mobility Management Function (AMF) of a communications system that includes an access node (AN) configured to communicate through a wireless air interface with user equipments (UEs) and that has a Session Management Function (SMF), is provided. The method includes receiving an indication of a Max Data Radio Bearer Integrity Protection, DRB-IP, rate indicating a maximum computational capacity of the UE to process DRBs that have integrity protection during Packet Data Unit (PDU) sessions. A PDU session establishment request NAS message is received from the UE for establishing a PDU session. A PDU session create message is communicated toward the SMF. A SMF message is received that contains an indication of an allocated DRB-IP rate for DRBs that are to be integrity protected for a PDU session being established.