5G UE Emergency PDU Session Security Handling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G communication systems, there is a need to protect user data over the control plane after an integrity check failure at the AMF and to prevent unnecessary runs of the security mode control procedure when a UE transfers an unauthenticated PDU session for emergency services from N1 mode to S1 mode.

Innovation Solution

The method involves identifying emergency PDU sessions, transmitting control plane service requests, performing integrity checks, and selecting null encryption algorithms when necessary, ensuring that only specific data types are transmitted without protection when null algorithms are used, and setting the selected EPS NAS algorithms to null to avoid unnecessary security mode control procedures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If integrity check is performed on control plane service request messages, then security is improved, but unnecessary security mode control procedures are triggered when UE transfers emergency PDU sessions

Engineering Contradiction:
ImprovesecurityVSAvoidunnecessary security mode control procedure
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies local quality by differentiating the integrity check process based on the type of data being transmitted. When the control plane service request message contains only emergency service data (second type data), the integrity check result is handled differently than when it contains non-emergency data (first type data). This localized differentiation allows the system to maintain security for non-emergency data while avoiding unnecessary security mode control procedures for emergency data transfers.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent inverts the conventional approach by not triggering security mode control procedure upon integrity check failure when the data is emergency service data. Instead of treating all integrity check failures uniformly, the system inverts the response: for emergency data, it allows the transfer to proceed without initiating security mode control, while for non-emergency data, it maintains the traditional security response. This inversion resolves the contradiction by prioritizing emergency service continuity over strict security protocol enforcement in specific contexts.

Inventive Principle:
Principle #13The other way round (Inversion)

2Productivity

If null encryption algorithm is selected for unauthenticated PDU session, then data transmission is enabled, but data security protection is reduced

Engineering Contradiction:
Improvedata transmissionVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies local quality by applying different security measures to different types of data. Emergency service data (second type data) is transmitted without encryption using null algorithm, while non-emergency user data (first type data) receives proper security protection. This localized security approach enables data transmission for emergency services while maintaining security for non-emergency data, resolving the contradiction between productivity and reliability.

Inventive Principle:
Principle #3Local quality

3Reliability

If integrity check fails for control plane service request, then security mode control procedure is initiated, but emergency service transmission is blocked

Engineering Contradiction:
ImprovesecurityVSAvoidemergency service transmission
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent inverts the conventional security response by allowing emergency service data transmission even when integrity check fails. Instead of blocking all transmissions with integrity check failures, the system inverts the behavior: emergency data (second type data) is allowed to proceed without triggering security mode control procedure, while non-emergency data follows the traditional blocking behavior. This inversion prioritizes emergency service continuity over strict security protocol enforcement.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent converts the potential harm of integrity check failure into a benefit by using it as a criterion to differentiate between emergency and non-emergency data handling. When integrity check fails, instead of uniformly blocking transmission, the system identifies that emergency service data should be allowed to proceed. The integrity check failure scenario is transformed into an opportunity to prioritize critical emergency communications, converting a security issue into a service quality improvement.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentEP4022953B1Method and apparatus for network security
Publication Date: 2024.12.25 SAMSUNG ELECTRONICS CO LTD
  • EP4022953B1 patent drawingFigure 1
  • EP4022953B1 patent drawingFigure 2
  • EP4022953B1 patent drawingFigure 3~4

AI summary

Method and apparatus for network security are disclosed. The method may comprises: identifying that an UE in idle mode, has an emergency protocol data unit (PDU) session; transmitting, to an AMF, a control plane service request (CPSR) message comprising data of a first type; receiving, from the AMF, a security mode command message indicating that an integrity check related to the CPSR message has failed; in response to receiving the security mode command message, identifying whether the CPSR message comprises the data of the first type including data of a second type, or the CPSR message comprises the data of the first type excluding the data of the second type; and transmitting the CPSR message excluding the data of the first type except the data of the second type.