Core Network Node Emergency Session Security Policy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 5G wireless communication systems, there is a challenge in correctly activating user plane security for Data Radio Bearers (DRBs) during emergency sessions, especially for unauthenticated users in Limited Service Mode (LSM), where null ciphering and null integrity protection are applied.
Innovation Solution
A method is implemented where a core network node determines that user plane security should not be activated for DRBs during emergency sessions. This is achieved by providing a user plane security policy to the radio access network node, indicating that confidentiality and integrity protection should not be activated for DRBs in such scenarios.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If user plane security is activated for DRBs during emergency sessions, then security protection is improved, but communication establishment complexity increases and authentication requirements are imposed
Solution Approach 1:
The patent applies different security policies to different bearers: control plane bearers (SRBs) maintain full security protection with encryption and integrity verification, while user plane bearers (DRBs) for emergency sessions use null security algorithms that provide no protection. This local differentiation allows emergency communications to establish quickly without authentication while maintaining security for normal operations.
Solution Approach 2:
The patent changes the security parameter configuration based on session type by setting the security algorithm to null ciphering and null integrity protection for emergency user plane bearers. This parameter change enables simplified communication establishment for emergency sessions while preserving full security mechanisms for regular sessions.
2Ease of operation
If null ciphering and null integrity protection are applied to control plane, then emergency session establishment is enabled for unauthenticated users, but user plane security activation becomes ambiguous
Solution Approach 1:
The patent segments the security activation logic by separately determining control plane security (which uses null algorithms for unauthenticated emergency sessions) and user plane security (which is explicitly deactivated for emergency sessions). This segmentation resolves the ambiguity by clearly distinguishing between the two plane requirements.
Solution Approach 2:
Instead of activating security for emergency sessions and then trying to simplify it, the patent inverts the approach by explicitly deactivating user plane security for emergency sessions while maintaining control plane security with null algorithms. This inversion clarifies the security state and enables unauthenticated access.
3Reliability
If full security protection is applied to both control plane and user plane, then communication security is improved, but authentication and key establishment procedures are required
Solution Approach 1:
The patent applies partial security action by providing full security protection for control plane communications (where authentication is needed) but no security protection for user plane emergency sessions (where authentication is not required). This partial application of security achieves the necessary protection without the time cost of authentication procedures for emergency user plane traffic.
Data Source
AI summary
A method is provided to operate a CN node to determine UP security activation. A UP session establishment request is obtained for a wireless device. An indication is obtained that the UP session establishment request is associated with an emergency session and/or that null ciphering and/or null integrity protection are applied to a CP associated with a CP session for the wireless device. It is determined that a UP should be configured for the UP session without activating integrity and/or confidentiality protection for the UP based on the indication. A UP security policy is provided to a RAN node associated with the wireless device, wherein the UP security policy indicates to configure the UP for the UP session without activating integrity and/or confidentiality protection based on determining that a UP should be configured for the UP session without activating integrity and/or confidentiality protection.


