Core Network Node Emergency Session Security Policy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G wireless communication systems, there is a challenge in correctly activating user plane security for Data Radio Bearers (DRBs) during emergency sessions, especially for unauthenticated users in Limited Service Mode (LSM), where null ciphering and null integrity protection are applied.

Innovation Solution

A method is implemented where a core network node determines that user plane security should not be activated for DRBs during emergency sessions. This is achieved by providing a user plane security policy to the radio access network node, indicating that confidentiality and integrity protection should not be activated for DRBs in such scenarios.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If user plane security is activated for DRBs during emergency sessions, then security protection is improved, but communication establishment complexity increases and authentication requirements are imposed

Engineering Contradiction:
Improvesecurity protectionVSAvoidcommunication establishment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies different security policies to different bearers: control plane bearers (SRBs) maintain full security protection with encryption and integrity verification, while user plane bearers (DRBs) for emergency sessions use null security algorithms that provide no protection. This local differentiation allows emergency communications to establish quickly without authentication while maintaining security for normal operations.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the security parameter configuration based on session type by setting the security algorithm to null ciphering and null integrity protection for emergency user plane bearers. This parameter change enables simplified communication establishment for emergency sessions while preserving full security mechanisms for regular sessions.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If null ciphering and null integrity protection are applied to control plane, then emergency session establishment is enabled for unauthenticated users, but user plane security activation becomes ambiguous

Engineering Contradiction:
Improveemergency session establishmentVSAvoiduser plane security activation
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the security activation logic by separately determining control plane security (which uses null algorithms for unauthenticated emergency sessions) and user plane security (which is explicitly deactivated for emergency sessions). This segmentation resolves the ambiguity by clearly distinguishing between the two plane requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Instead of activating security for emergency sessions and then trying to simplify it, the patent inverts the approach by explicitly deactivating user plane security for emergency sessions while maintaining control plane security with null algorithms. This inversion clarifies the security state and enables unauthenticated access.

Inventive Principle:
Principle #13The other way round (Inversion)

3Reliability

If full security protection is applied to both control plane and user plane, then communication security is improved, but authentication and key establishment procedures are required

Engineering Contradiction:
Improvecommunication securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial security action by providing full security protection for control plane communications (where authentication is needed) but no security protection for user plane emergency sessions (where authentication is not required). This partial application of security achieves the necessary protection without the time cost of authentication procedures for emergency user plane traffic.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250141935A1Methods providing management of emergency sessions and related devices and nodes
Publication Date: 2025.05.01 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20250141935A1 patent drawing
  • US20250141935A1 patent drawing
  • US20250141935A1 patent drawing

AI summary

A method is provided to operate a CN node to determine UP security activation. A UP session establishment request is obtained for a wireless device. An indication is obtained that the UP session establishment request is associated with an emergency session and/or that null ciphering and/or null integrity protection are applied to a CP associated with a CP session for the wireless device. It is determined that a UP should be configured for the UP session without activating integrity and/or confidentiality protection for the UP based on the indication. A UP security policy is provided to a RAN node associated with the wireless device, wherein the UP security policy indicates to configure the UP for the UP session without activating integrity and/or confidentiality protection based on determining that a UP should be configured for the UP session without activating integrity and/or confidentiality protection.