Dynamic UP Security Termination Control in 5G RAN
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 5G wireless communication networks lack a mechanism to dynamically decide when to use User Plane (UP) encryption and/or integrity protection for data between User Equipment (UE) and the Radio Access Network (RAN), limiting flexibility in security management.
Innovation Solution
A method and system that allow User Equipment (UE) to transmit a Protocol Data Unit (PDU) Session Establishment Request to a Session Management Function (SMF), receiving a policy decision on security protection for UP data terminating in the RAN, and activating encryption and/or integrity protection accordingly, enabling flexible control of UP protection on a per-Slice or per-PDU session basis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security termination for UP data is implemented in the base station or core network, then security protection is provided, but the system lacks flexibility to dynamically switch security on and off
Solution Approach 1:
The patent implements dynamic security control by introducing a mechanism that allows the core network to receive indications from the RAN about whether to activate or deactivate security termination for UP data. This enables the security configuration to change dynamically based on network conditions, user preferences, and policy requirements, resolving the contradiction between providing security protection and maintaining flexibility.
Solution Approach 2:
The system changes the security parameter state by allowing dynamic switching between security termination modes (on/off) through network signaling. The core network can modify security parameters based on received indications, enabling adaptive security management that responds to changing operational requirements without compromising the fundamental security protection capability.
2Ease of manufacture
If security termination is fixed in base station or core network, then implementation is simple, but flexibility in security management is limited
Solution Approach 1:
The patent creates a universal security management mechanism that can operate in multiple modes: security termination can be implemented in the base station, in the core network, or dynamically switched between them. This multi-functional approach maintains implementation simplicity while enabling flexible security management through a unified indication-based control mechanism that works across different deployment scenarios.
3Ease of operation
If no mechanism is provided to decide when to use UP encryption and integrity protection, then system operation is simple, but security adaptability is reduced
Solution Approach 1:
The system enables self-service security management where the RAN autonomously evaluates local conditions (user preferences, policy requirements, network state) and generates indications to the core network about whether security termination should be activated. This maintains operational simplicity at the user level while providing adaptive security decision-making through automated network-based evaluation and dynamic configuration updates.
Data Source
AI summary
A UE configured to perform a process that includes transmitting, via a RAN node, a Protocol Data Unit (PDU) Session Establishment Request message toward a Session Management Function (SMF). The process also includes, after transmitting the PDU Session Establishment Request message, the UE receiving from the RAN node a Radio Resource Control (RRC) Connection Reconfiguration message comprising: i) a PDU session identifier (ID) identifying a PDU session, ii) a PDU Session Establishment Accept message generated by the SMF, and iii) indications for the activation of user plane (UP) integrity protection and ciphering for each data radio bearer (DRB) belonging to the PDU session according to a security policy received by the RAN node.


