5G UE Emergency PDU Session Security Handling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 5G communication systems, there is a need to protect user data over the control plane after an integrity check failure at the AMF and to prevent unnecessary runs of the security mode control procedure when a UE transfers an unauthenticated PDU session for emergency services from N1 mode to S1 mode.
Innovation Solution
The method involves identifying emergency PDU sessions, transmitting control plane service requests, performing integrity checks, and selecting null encryption algorithms when necessary, ensuring that only specific data types are transmitted without protection when null algorithms are used, and setting the selected EPS NAS algorithms to null to avoid unnecessary security mode control procedures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If integrity check is performed on control plane service request messages, then security is improved, but unnecessary security mode control procedures are triggered when UE transfers emergency PDU sessions
Solution Approach 1:
The patent applies local quality by differentiating the integrity check process based on the type of data being transmitted. When the control plane service request message contains only emergency service data (second type data), the integrity check result is handled differently than when it contains non-emergency data (first type data). This localized differentiation allows the system to maintain security for non-emergency data while avoiding unnecessary security mode control procedures for emergency data transfers.
Solution Approach 2:
The patent inverts the conventional approach by not triggering security mode control procedure upon integrity check failure when the data is emergency service data. Instead of treating all integrity check failures uniformly, the system inverts the response: for emergency data, it allows the transfer to proceed without initiating security mode control, while for non-emergency data, it maintains the traditional security response. This inversion resolves the contradiction by prioritizing emergency service continuity over strict security protocol enforcement in specific contexts.
2Productivity
If null encryption algorithm is selected for unauthenticated PDU session, then data transmission is enabled, but data security protection is reduced
Solution Approach 1:
The patent applies local quality by applying different security measures to different types of data. Emergency service data (second type data) is transmitted without encryption using null algorithm, while non-emergency user data (first type data) receives proper security protection. This localized security approach enables data transmission for emergency services while maintaining security for non-emergency data, resolving the contradiction between productivity and reliability.
3Reliability
If integrity check fails for control plane service request, then security mode control procedure is initiated, but emergency service transmission is blocked
Solution Approach 1:
The patent inverts the conventional security response by allowing emergency service data transmission even when integrity check fails. Instead of blocking all transmissions with integrity check failures, the system inverts the behavior: emergency data (second type data) is allowed to proceed without triggering security mode control procedure, while non-emergency data follows the traditional blocking behavior. This inversion prioritizes emergency service continuity over strict security protocol enforcement.
Solution Approach 2:
The patent converts the potential harm of integrity check failure into a benefit by using it as a criterion to differentiate between emergency and non-emergency data handling. When integrity check fails, instead of uniformly blocking transmission, the system identifies that emergency service data should be allowed to proceed. The integrity check failure scenario is transformed into an opportunity to prioritize critical emergency communications, converting a security issue into a service quality improvement.
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
Method and apparatus for network security are disclosed. The method may comprises: identifying that an UE in idle mode, has an emergency protocol data unit (PDU) session; transmitting, to an AMF, a control plane service request (CPSR) message comprising data of a first type; receiving, from the AMF, a security mode command message indicating that an integrity check related to the CPSR message has failed; in response to receiving the security mode command message, identifying whether the CPSR message comprises the data of the first type including data of a second type, or the CPSR message comprises the data of the first type excluding the data of the second type; and transmitting the CPSR message excluding the data of the first type except the data of the second type.