Core Network Node Registration Security Context Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless communication networks, especially in 5G networks with multiple network slices, the initial core network node may not be able to serve a wireless device or may not be the most suitable for registration, requiring re-routing of registration requests and transfer of security contexts to a target core network node, which poses challenges due to the lack of direct communication interfaces between these nodes.

Innovation Solution

The initial core network node uses the radio access network to re-route the registration request and transfer the encrypted security context to the target core network node, employing cryptographic keying material specific to or shared with the target node to ensure secure transfer, even in the absence of a direct interface.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the initial core network node re-routes the registration request through the radio access network to a target core network node without a direct interface, then network flexibility and adaptability are improved, but security risks increase due to the lack of direct communication interface

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a common network node as an intermediary to enable secure communication between the initial core network node and the target core network node. This common network node provides a trusted path for transferring the security context, allowing re-routing while maintaining security through the intermediary's authentication and encryption capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies preliminary action by establishing a security context transfer mechanism in advance. The initial core network node encrypts the security context using cryptographic material before transfer, and the target core network node is pre-configured with the necessary decryption capabilities. This preliminary security setup enables safe re-routing without exposing sensitive data during transmission.

Inventive Principle:
Principle #10Preliminary action

2Device complexity

If the security context is transferred through the radio access network without encryption, then the transfer process is simpler, but the security context becomes vulnerable to attacks

Engineering Contradiction:
Improvetransfer process complexityVSAvoidsecurity context protection
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The initial core network node performs preliminary encryption of the security context using cryptographic material specific to the target core network node before transferring it through the radio access network. This advance security preparation ensures that even though the transfer path is simple, the data is protected against interception and manipulation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The common network node acts as a secure intermediary that facilitates encrypted transfer of the security context. It provides the cryptographic infrastructure needed for secure communication, allowing the transfer process to remain simple while maintaining high security through the intermediary's encryption and authentication mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If multiple network slices are deployed with separate core network nodes, then network functionality and service differentiation are improved, but the complexity of routing and context transfer increases

Engineering Contradiction:
Improvenetwork slice functionalityVSAvoidrouting complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The common network node serves multiple network slices and acts as a universal intermediary for all security context transfers between core network nodes. This multi-functional approach allows different network slices to be served by separate core network nodes while using a shared security infrastructure, reducing the overall routing and transfer complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The common network node provides a standardized intermediary layer that handles security context transfers for multiple network slices. By centralizing the security functions in this common node, the patent simplifies the routing complexity while maintaining the ability to serve multiple network slices with specialized core network nodes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240129731A1Registration in a Wireless Communication Network
Publication Date: 2024.04.18 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20240129731A1 patent drawing
  • US20240129731A1 patent drawing
  • US20240129731A1 patent drawing

AI summary

A core network node (16) is configured for use in a wireless communication network (10). The core network node (16 receives a registration request (14) that requests registration of a wireless device (12) with the wireless communication network (10). The core network node (16) protects a security context (20) shared between the wireless device (12) and the core network node (16, e.g., including encrypting the security context (20). The core network node (16) transmits, to a radio network node (23) in the wireless communication network (10), signaling (24) that includes the registration request (14) and the protected security context (20P). In some embodiments, the signaling (24) indicates the registration request (14) and the protected security context (20P) are to be re-routed to a target core network node (18) in the wireless communication network (10).