AUSF Parameter Encryption for 5G Roaming Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 5G networks, parameters sent from the Home Public Land Mobile Network (HPLMN) to a terminal can be intercepted or modified by entities in the Visited Public Land Mobile Network (VPLMN) during forwarding, compromising security.
Innovation Solution
The Authentication Server Function (AUSF) entity in the HPLMN obtains a security algorithm and generates a key for securing parameter transmission, performing security protection processing on parameters before forwarding them through the VPLMN, ensuring they remain unmodified and secure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If parameters are forwarded through VPLMN entities, then network roaming capability is enabled, but security of parameter transmission deteriorates due to potential interception or modification
Solution Approach 1:
The patent applies preliminary anti-action by performing security protection processing on parameters before they are forwarded through VPLMN entities. The AUSF entity encrypts and protects parameters in advance, preventing potential interception or modification by intermediate nodes, thus countering security risks before they can manifest
Solution Approach 2:
The patent introduces an intermediary security protection mechanism where the AUSF entity acts as a mediator that encrypts parameters using security algorithms and keys before forwarding. This intermediary layer ensures that even though parameters pass through VPLMN entities, they remain protected from unauthorized access or modification
2Reliability
If security protection processing is performed on parameters, then transmission security is improved, but system complexity increases due to additional security processing steps
Solution Approach 1:
The patent applies universality by having the AUSF entity perform multiple functions: it not only authenticates users but also generates security keys, selects security algorithms, and encrypts parameters. This multi-functionality consolidates security operations into a single entity, avoiding the need for separate security infrastructure and reducing overall system complexity
Solution Approach 2:
The patent changes the state of parameters by transforming them from plaintext to encrypted form using security algorithms and keys. This parameter transformation ensures security while maintaining the integrity and usability of the original data, achieving security protection without fundamentally altering the parameter structure
Data Source
Figure 1
Figure 2
Figure 3
AI summary
This application provides a parameter protection method and device, and a system. The method includes: obtaining, by an AUSF entity in an HPLMN, a security algorithm, and generating a key, where the key is used to protect transmission of a parameter between a terminal and the HPLMN; sending, by another entity in the HPLMN, the parameter to the AUSF entity, where the another entity is an entity that needs to send the parameter to the terminal; and performing, by the AUSF entity, security protection processing on the parameter based on the security algorithm and the key. The AUSF entity performs, based on the obtained security algorithm and the generated key, security protection processing on the parameter that needs to be sent to the terminal, and then the HPLMN protects the parameter that is to be sent to the terminal. In a process in which the parameter is forwarded to the terminal by using an entity in a VPLMN, because security protection has been performed on the parameter, the parameter is not intercepted or modified by the entity in the VPLMN, thereby improving security of the parameter sent by the HPLMN to the terminal during the transmission.