Dedicated Core Network Redirection Security Context Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing message flows for Dedicated Core Network in 3GPP systems lead to signaling overload and redundancy in Authentication and Key Agreement (AKA) and Non-Access Stratum (NAS) Security Mode Command (SMC) procedures, causing inefficiencies and overload on devices and interfaces due to redundant security context retrieval.

Innovation Solution

A network system and method where a first node establishes a secure connection with UE and redirects it to a second node, with the first node sending necessary information to the second node through a radio base station for security context retrieval, thereby skipping redundant AKA and NAS SMC procedures in the second node.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the UE is redirected to a specific MME for Dedicated Core Network support, then the appropriate core network can be ensured for specific subscriber types, but signaling overload and redundancy occur in AKA and NAS SMC procedures

Engineering Contradiction:
ImproveDedicated Core Network supportVSAvoidSignaling overload
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The first MME performs AKA and NAS SMC procedures in advance before redirecting the UE to the specific MME. The security context is established preliminarily, so when the UE is redirected, the specific MME can retrieve the existing security context without performing redundant authentication procedures, thus reducing signaling overload while ensuring Dedicated Core Network support

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The first MME acts as an intermediary that facilitates the redirection process. It performs the initial authentication with the UE, then transfers the security context to the specific MME through the HSS or direct interface. This intermediary role allows the specific MME to avoid redundant authentication while maintaining security, resolving the contradiction between Dedicated Core Network support and signaling overload

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the specific MME performs AKA and NAS SMC procedures after redirection, then secure connection can be established with the UE, but computational load and processing time increase on the specific MME

Engineering Contradiction:
ImproveSecure connection establishmentVSAvoidProcessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The authentication and security context establishment are performed in advance by the first MME before the UE is redirected to the specific MME. This preliminary action ensures that when the UE arrives at the specific MME, the secure connection framework is already in place, and the specific MME only needs to retrieve and activate the existing security context, significantly reducing processing time while maintaining secure connection establishment

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If the security context is retrieved from the old MME using GUTI, then the redirection process can be initiated, but signaling overload occurs if the old MME has removed the security context

Engineering Contradiction:
ImproveRedirection processVSAvoidSignaling overload
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The first MME serves as an intermediary that maintains the security context temporarily after the UE is redirected. When the specific MME needs to retrieve the security context, the first MME provides it through a direct interface rather than requiring the specific MME to contact the old MME (which may have already removed the context). This intermediary approach ensures smooth redirection while avoiding signaling overload from failed context retrieval attempts

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11477726B2Apparatus, system and method for dedicated core network
Publication Date: 2022.10.18 NEC CORP
  • US11477726B2 patent drawing
  • US11477726B2 patent drawing
  • US11477726B2 patent drawing

AI summary

In order for more effectively supporting a Dedicated Core Network, there is provided a network system including a first node (30) that establishes secure connection with a UE (10) initially attempting to attach to a network, through a radio base station (20), and a second node (40) to which the UE (10) is redirected from the first node (30) through the radio base station (20). Upon the redirection, the first node (30) sends information on the first node (30) itself to the second node (40) through the radio base station (20). The second node (40) uses the information to retrieve security context necessary for establishing the connection with the UE (10) from the first node (30).