Bearer Signaling for On-Demand User Plane Security in 4G/5G NSA

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The transition from 4G to 5G networks introduces the need for an on-demand user plane security protection mechanism, which is not supported in conventional 4G networks, posing a challenge in implementing dual connectivity in a non-standalone (NSA) deployment manner.

Innovation Solution

A security activation method involving a first access network device requesting resource allocation from a second access network device, exchanging indication and security status information to enable user plane security protection based on terminal device capabilities and policies, enhancing processing logic in dual connectivity scenarios.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the on-demand user plane security protection mechanism is introduced to the 4G network, then user plane security flexibility is improved, but device complexity increases due to enhanced processing logic requirements in access network devices

Engineering Contradiction:
Improveuser plane securityVSAvoidprocessing logic complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security activation process into distinct phases: capability indication from terminal to access network device, policy determination by the access network device, and security activation status transmission back to the terminal. This segmentation allows each component to handle specific tasks independently, improving security implementation while managing complexity through modular processing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by having the terminal device indicate its user plane security capability in advance during the connection establishment phase. The access network device then determines the security policy beforehand based on this indication and network requirements, enabling security activation without adding complexity to real-time processing.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the first access network device sends indication information and security status to the terminal device, then user plane security protection is enabled, but signaling overhead increases

Engineering Contradiction:
Improveuser plane security protectionVSAvoidsignaling overhead
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent merges the security activation status transmission with existing bearer setup or modification signaling messages. By combining multiple functions (bearer configuration and security activation indication) into a single signaling exchange, the patent enables user plane security protection while minimizing additional signaling overhead.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The access network device uses universal signaling messages that serve multiple purposes: bearer management and security activation. This multi-functionality approach allows the same signaling infrastructure to handle both data transmission setup and security configuration, reducing the need for separate dedicated security signaling channels.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12425847B2Security activation method and communication apparatus
Publication Date: 2025.09.23 HUAWEI TECH CO LTD
  • US12425847B2 patent drawing
  • US12425847B2 patent drawing
  • US12425847B2 patent drawing

AI summary

This application provides security activation methods and communication apparatuses. In an example method, a first access network device in a first communication standard requests a second access network device in a second communication standard to allocate a resource for dual connectivity of a terminal device, and sends, to the second access network device, a user plane security policy. The first access network device further receives identification information of a bearer and a security activation status from the second access network device and sends the identification information of the bearer and the security activation status to the terminal device.