5G CIoT Truncated Parameter Protection Through NAS Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G systems, truncated parameters like the 5G-S-TMSI are vulnerable to tampering due to lack of AS security protection, leading to denial of service attacks and network access failures.

Innovation Solution

Implement NAS security protection for truncated parameters by a mobility management network element, ensuring the truncated parameters are not tampered with, using a method that includes determining terminal conditions and sending protected NAS messages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the terminal uses control plane CIoT 5GS optimization function, then the network access efficiency is improved, but the truncated parameter becomes vulnerable to tampering

Engineering Contradiction:
Improvenetwork access efficiencyVSAvoidtruncated parameter integrity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces an integrity protection mechanism as an intermediary layer between the truncated parameter and the terminal. The access network device generates an integrity protection code based on the truncated parameter and sends it to the terminal. The terminal uses this code to verify the integrity of the received truncated parameter, preventing tampering while maintaining the efficiency benefits of control plane CIoT optimization.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the state of the truncated parameter by adding integrity protection information to it. The access network device modifies the original truncated parameter by appending or associating an integrity protection code, transforming it from a vulnerable parameter into a protected parameter that can be verified for integrity without affecting the original truncation efficiency.

Inventive Principle:
Principle #35Parameter changes

2Device complexity

If the access network device sends truncated parameter without AS security protection, then the device complexity is reduced, but the security risk increases

Engineering Contradiction:
Improvesecurity protection mechanismVSAvoidparameter tampering risk
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by having the access network device generate and attach integrity protection information to the truncated parameter before sending it to the terminal. This preventive measure is taken in advance, so when the terminal receives the parameter, it already has the means to verify integrity, eliminating the need for complex post-reception security verification mechanisms.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If the terminal receives tampered truncated parameter, then the attack success rate increases, but the network access fails

Engineering Contradiction:
Improveattack effectivenessVSAvoidnetwork access success
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where the terminal verifies the integrity of the received truncated parameter using the integrity protection code. If verification fails (indicating tampering), the terminal rejects the parameter and can request retransmission or report the incident. This feedback loop prevents tampered parameters from causing successful attacks while maintaining network access reliability.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12432562B2Method for protecting truncated parameter and apparatus
Publication Date: 2025.09.30 HUAWEI TECH CO LTD
  • US12432562B2 patent drawing
  • US12432562B2 patent drawing
  • US12432562B2 patent drawing

AI summary

A method for protecting a truncated parameter includes that a mobility management network element determines whether a terminal that accesses a network meets a preset condition, where the preset condition includes that the terminal uses a control plane cellular Internet of things (CIoT) 5th generation system (5GS) optimization function. The mobility management network element sends, to the terminal when the terminal meets the preset condition, a downlink non-access stratum (NAS) message on which NAS security protection is performed using a NAS security context, where the downlink NAS message includes a truncated parameter.