Cloud MME Security Context Repository for Signaling Overload

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The current EPS architecture experiences signaling overload during mobility and virtualization due to redundant AKA/NAS SMC procedures, particularly affecting MMEs, as UE context is frequently retrieved and removed, leading to increased load on devices and interfaces.

Innovation Solution

Implementing a cloud MME (cMME) that offloads security context storage, allowing MMEs to securely connect with it, reducing the need for redundant procedures by storing and retrieving security context from the cMME, thereby simplifying MME functionalities and minimizing signaling overload.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the new MME retrieves UE context from the old MME/SGSN during mobility, then the UE context can be obtained for continuity, but redundant AKA/NAS SMC procedures are triggered causing signaling overload

Engineering Contradiction:
ImproveUE context continuityVSAvoidsignaling overload
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent extracts the security context storage function from the MME to a separate security context repository. This allows the new MME to directly retrieve security context from the repository without triggering redundant AKA/NAS SMC procedures, thus maintaining UE context continuity while eliminating signaling overload.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a security context repository as an intermediary between the MME and UE context management. This intermediary stores security context centrally, enabling the new MME to retrieve context without contacting the old MME, thereby preventing redundant security procedures and reducing signaling load.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If the old MME/SGSN removes the UE context after mobility, then storage space is freed, but the new MME must perform redundant AKA/NAS SMC procedures

Engineering Contradiction:
ImproveMME resource availabilityVSAvoidredundant procedure time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent extracts security context from individual MME/SGSN instances and stores it centrally in a security context repository. This allows the old MME/SGSN to remove local context for resource efficiency while the new MME retrieves it from the repository, eliminating redundant procedures and time loss.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements preliminary storage of security context in the repository before mobility occurs. When mobility happens, the new MME can directly retrieve the pre-stored context without performing redundant AKA/NAS SMC procedures, thus saving time and avoiding unnecessary operations.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If virtualization creates and removes MME on demand, then resource efficiency is improved, but frequent UE context retrieval and removal causes overload

Engineering Contradiction:
ImproveMME scalabilityVSAvoidinterface overload
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The patent extracts security context management from virtualized MME instances to a separate security context repository. This allows MMEs to be created and removed on demand for resource efficiency while the repository maintains persistent security context, preventing interface overload during virtualization operations.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a universal security context repository that serves all MME instances regardless of their lifecycle. This repository provides consistent security context retrieval and storage capabilities across multiple virtualized MMEs, enabling scalable MME management without causing interface overload.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3547739B1Apparatus and method for security management
Publication Date: 2024.09.18 NEC CORP
  • EP3547739B1 patent drawingFigure 1
  • EP3547739B1 patent drawingFigure 2
  • EP3547739B1 patent drawingFigure 3

AI summary

There is provided a network system including one or more first MMEs (30), and a second MME (40) separated from the first MMEs (30). In one of operation cases, the first MME (30) pushes, to the second MME (40), security context for a UE (10) that attaches to the first MME (30). The second MME (40) stores the security context. The first MME (30) further pushes the latest security context to the second MME (40), during a switch-off procedure for the first MME (30). The second MME (40) updates the stored security context with the latest security context. The first MME (30) pulls the security context from the second MME (40), when the UE (10) re-attaches to the first MME (30) or is handovered from different one of the first MMEs (30).