Dynamic UP Security Termination Control in 5G RAN

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G wireless communication networks lack a mechanism to dynamically decide when to use User Plane (UP) encryption and/or integrity protection for data between User Equipment (UE) and the Radio Access Network (RAN), limiting flexibility in security management.

Innovation Solution

A method and system that allow User Equipment (UE) to transmit a Protocol Data Unit (PDU) Session Establishment Request to a Session Management Function (SMF), receiving a policy decision on security protection for UP data terminating in the RAN, and activating encryption and/or integrity protection accordingly, enabling flexible control of UP protection on a per-Slice or per-PDU session basis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security termination for UP data is implemented in the base station or core network, then security protection is provided, but the system lacks flexibility to dynamically switch security on and off

Engineering Contradiction:
Improvesecurity protectionVSAvoiddynamic security control
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security control by introducing a mechanism that allows the core network to receive indications from the RAN about whether to activate or deactivate security termination for UP data. This enables the security configuration to change dynamically based on network conditions, user preferences, and policy requirements, resolving the contradiction between providing security protection and maintaining flexibility.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the security parameter state by allowing dynamic switching between security termination modes (on/off) through network signaling. The core network can modify security parameters based on received indications, enabling adaptive security management that responds to changing operational requirements without compromising the fundamental security protection capability.

Inventive Principle:
Principle #35Parameter changes

2Ease of manufacture

If security termination is fixed in base station or core network, then implementation is simple, but flexibility in security management is limited

Engineering Contradiction:
Improveimplementation simplicityVSAvoidsecurity management flexibility
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal security management mechanism that can operate in multiple modes: security termination can be implemented in the base station, in the core network, or dynamically switched between them. This multi-functional approach maintains implementation simplicity while enabling flexible security management through a unified indication-based control mechanism that works across different deployment scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If no mechanism is provided to decide when to use UP encryption and integrity protection, then system operation is simple, but security adaptability is reduced

Engineering Contradiction:
Improvesystem operation simplicityVSAvoidsecurity decision flexibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The system enables self-service security management where the RAN autonomously evaluates local conditions (user preferences, policy requirements, network state) and generates indications to the core network about whether security termination should be activated. This maintains operational simplicity at the user level while providing adaptive security decision-making through automated network-based evaluation and dynamic configuration updates.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20240259792A1Security solution for switching on and off security for up data between UE and ran in 5g
Publication Date: 2024.08.01 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20240259792A1 patent drawing
  • US20240259792A1 patent drawing
  • US20240259792A1 patent drawing

AI summary

A UE configured to perform a process that includes transmitting, via a RAN node, a Protocol Data Unit (PDU) Session Establishment Request message toward a Session Management Function (SMF). The process also includes, after transmitting the PDU Session Establishment Request message, the UE receiving from the RAN node a Radio Resource Control (RRC) Connection Reconfiguration message comprising: i) a PDU session identifier (ID) identifying a PDU session, ii) a PDU Session Establishment Accept message generated by the SMF, and iii) indications for the activation of user plane (UP) integrity protection and ciphering for each data radio bearer (DRB) belonging to the PDU session according to a security policy received by the RAN node.