Core Network Node Registration Security Context Transfer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In wireless communication networks, especially in 5G networks with multiple network slices, the initial core network node may not be able to serve a wireless device or may not be the most suitable for registration, requiring re-routing of registration requests and transfer of security contexts to a target core network node, which poses challenges due to the lack of direct communication interfaces between these nodes.
Innovation Solution
The initial core network node uses the radio access network to re-route the registration request and transfer the encrypted security context to the target core network node, employing cryptographic keying material specific to or shared with the target node to ensure secure transfer, even in the absence of a direct interface.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the initial core network node re-routes the registration request through the radio access network to a target core network node without a direct interface, then network flexibility and adaptability are improved, but security risks increase due to the lack of direct communication interface
Solution Approach 1:
The patent introduces a common network node as an intermediary to enable secure communication between the initial core network node and the target core network node. This common network node provides a trusted path for transferring the security context, allowing re-routing while maintaining security through the intermediary's authentication and encryption capabilities.
Solution Approach 2:
The patent applies preliminary action by establishing a security context transfer mechanism in advance. The initial core network node encrypts the security context using cryptographic material before transfer, and the target core network node is pre-configured with the necessary decryption capabilities. This preliminary security setup enables safe re-routing without exposing sensitive data during transmission.
2Device complexity
If the security context is transferred through the radio access network without encryption, then the transfer process is simpler, but the security context becomes vulnerable to attacks
Solution Approach 1:
The initial core network node performs preliminary encryption of the security context using cryptographic material specific to the target core network node before transferring it through the radio access network. This advance security preparation ensures that even though the transfer path is simple, the data is protected against interception and manipulation.
Solution Approach 2:
The common network node acts as a secure intermediary that facilitates encrypted transfer of the security context. It provides the cryptographic infrastructure needed for secure communication, allowing the transfer process to remain simple while maintaining high security through the intermediary's encryption and authentication mechanisms.
3Adaptability or versatility
If multiple network slices are deployed with separate core network nodes, then network functionality and service differentiation are improved, but the complexity of routing and context transfer increases
Solution Approach 1:
The common network node serves multiple network slices and acts as a universal intermediary for all security context transfers between core network nodes. This multi-functional approach allows different network slices to be served by separate core network nodes while using a shared security infrastructure, reducing the overall routing and transfer complexity.
Solution Approach 2:
The common network node provides a standardized intermediary layer that handles security context transfers for multiple network slices. By centralizing the security functions in this common node, the patent simplifies the routing complexity while maintaining the ability to serve multiple network slices with specialized core network nodes.
Data Source
AI summary
A core network node (16) is configured for use in a wireless communication network (10). The core network node (16 receives a registration request (14) that requests registration of a wireless device (12) with the wireless communication network (10). The core network node (16) protects a security context (20) shared between the wireless device (12) and the core network node (16, e.g., including encrypting the security context (20). The core network node (16) transmits, to a radio network node (23) in the wireless communication network (10), signaling (24) that includes the registration request (14) and the protected security context (20P). In some embodiments, the signaling (24) indicates the registration request (14) and the protected security context (20P) are to be re-routed to a target core network node (18) in the wireless communication network (10).


