Dedicated Core Network Redirection Security Context Transfer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing message flows for Dedicated Core Network in 3GPP systems lead to signaling overload and redundancy in Authentication and Key Agreement (AKA) and Non-Access Stratum (NAS) Security Mode Command (SMC) procedures, causing inefficiencies and overload on devices and interfaces due to redundant security context retrieval.
Innovation Solution
A network system and method where a first node establishes a secure connection with UE and redirects it to a second node, with the first node sending necessary information to the second node through a radio base station for security context retrieval, thereby skipping redundant AKA and NAS SMC procedures in the second node.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the UE is redirected to a specific MME for Dedicated Core Network support, then the appropriate core network can be ensured for specific subscriber types, but signaling overload and redundancy occur in AKA and NAS SMC procedures
Solution Approach 1:
The first MME performs AKA and NAS SMC procedures in advance before redirecting the UE to the specific MME. The security context is established preliminarily, so when the UE is redirected, the specific MME can retrieve the existing security context without performing redundant authentication procedures, thus reducing signaling overload while ensuring Dedicated Core Network support
Solution Approach 2:
The first MME acts as an intermediary that facilitates the redirection process. It performs the initial authentication with the UE, then transfers the security context to the specific MME through the HSS or direct interface. This intermediary role allows the specific MME to avoid redundant authentication while maintaining security, resolving the contradiction between Dedicated Core Network support and signaling overload
2Reliability
If the specific MME performs AKA and NAS SMC procedures after redirection, then secure connection can be established with the UE, but computational load and processing time increase on the specific MME
Solution Approach 1:
The authentication and security context establishment are performed in advance by the first MME before the UE is redirected to the specific MME. This preliminary action ensures that when the UE arrives at the specific MME, the secure connection framework is already in place, and the specific MME only needs to retrieve and activate the existing security context, significantly reducing processing time while maintaining secure connection establishment
3Ease of operation
If the security context is retrieved from the old MME using GUTI, then the redirection process can be initiated, but signaling overload occurs if the old MME has removed the security context
Solution Approach 1:
The first MME serves as an intermediary that maintains the security context temporarily after the UE is redirected. When the specific MME needs to retrieve the security context, the first MME provides it through a direct interface rather than requiring the specific MME to contact the old MME (which may have already removed the context). This intermediary approach ensures smooth redirection while avoiding signaling overload from failed context retrieval attempts
Data Source
AI summary
In order for more effectively supporting a Dedicated Core Network, there is provided a network system including a first node (30) that establishes secure connection with a UE (10) initially attempting to attach to a network, through a radio base station (20), and a second node (40) to which the UE (10) is redirected from the first node (30) through the radio base station (20). Upon the redirection, the first node (30) sends information on the first node (30) itself to the second node (40) through the radio base station (20). The second node (40) uses the information to retrieve security context necessary for establishing the connection with the UE (10) from the first node (30).


