AUSF Parameter Encryption for 5G Roaming Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G networks, parameters sent from the Home Public Land Mobile Network (HPLMN) to a terminal can be intercepted or modified by entities in the Visited Public Land Mobile Network (VPLMN) during forwarding, compromising security.

Innovation Solution

The Authentication Server Function (AUSF) entity in the HPLMN obtains a security algorithm and generates a key for securing parameter transmission, performing security protection processing on parameters before forwarding them through the VPLMN, ensuring they remain unmodified and secure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If parameters are forwarded through VPLMN entities, then network roaming capability is enabled, but security of parameter transmission deteriorates due to potential interception or modification

Engineering Contradiction:
Improvenetwork roaming capabilityVSAvoidsecurity of parameter transmission
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary anti-action by performing security protection processing on parameters before they are forwarded through VPLMN entities. The AUSF entity encrypts and protects parameters in advance, preventing potential interception or modification by intermediate nodes, thus countering security risks before they can manifest

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent introduces an intermediary security protection mechanism where the AUSF entity acts as a mediator that encrypts parameters using security algorithms and keys before forwarding. This intermediary layer ensures that even though parameters pass through VPLMN entities, they remain protected from unauthorized access or modification

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security protection processing is performed on parameters, then transmission security is improved, but system complexity increases due to additional security processing steps

Engineering Contradiction:
Improvetransmission securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by having the AUSF entity perform multiple functions: it not only authenticates users but also generates security keys, selects security algorithms, and encrypts parameters. This multi-functionality consolidates security operations into a single entity, avoiding the need for separate security infrastructure and reducing overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the state of parameters by transforming them from plaintext to encrypted form using security algorithms and keys. This parameter transformation ensures security while maintaining the integrity and usability of the original data, achieving security protection without fundamentally altering the parameter structure

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3691316B1Parameter protection method, device and system
Publication Date: 2022.02.16 HUAWEI TECH CO LTD
  • EP3691316B1 patent drawingFigure 1
  • EP3691316B1 patent drawingFigure 2
  • EP3691316B1 patent drawingFigure 3

AI summary

This application provides a parameter protection method and device, and a system. The method includes: obtaining, by an AUSF entity in an HPLMN, a security algorithm, and generating a key, where the key is used to protect transmission of a parameter between a terminal and the HPLMN; sending, by another entity in the HPLMN, the parameter to the AUSF entity, where the another entity is an entity that needs to send the parameter to the terminal; and performing, by the AUSF entity, security protection processing on the parameter based on the security algorithm and the key. The AUSF entity performs, based on the obtained security algorithm and the generated key, security protection processing on the parameter that needs to be sent to the terminal, and then the HPLMN protects the parameter that is to be sent to the terminal. In a process in which the parameter is forwarded to the terminal by using an entity in a VPLMN, because security protection has been performed on the parameter, the parameter is not intercepted or modified by the entity in the VPLMN, thereby improving security of the parameter sent by the HPLMN to the terminal during the transmission.