Integrity Protected Registration Requests for 5G EPS Mobility
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The integration of 5G and Evolved Packet System (EPS) networks poses security risks due to the lack of effective mechanisms for protecting registration requests against threats like man-in-the-middle or replay attacks, particularly during mobility operations where User Equipment (UE) transitions between different network technologies.
Innovation Solution
Implementing a method where User Equipment (UE) generates and sends integrity-protected registration requests using Message Authentication Codes (MAC) shared with Mobility Management Entity (MME) or Access and Mobility Management Function (AMF) nodes, ensuring secure communication and authentication across network transitions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If registration requests are sent without integrity protection during inter-network mobility, then the registration process is simple and fast, but the system becomes vulnerable to man-in-the-middle and replay attacks
Solution Approach 1:
The patent applies preliminary action by pre-establishing security contexts and key material between network functions before mobility events occur. The source MME and target AMF exchange security parameters in advance, so that when registration requests are transmitted, integrity protection mechanisms are already in place and configured, reducing the complexity burden during the actual registration process
Solution Approach 2:
The patent uses an intermediary approach by introducing integrity protection mechanisms (MACs) as mediators between the UE and network functions. These MACs act as cryptographic intermediaries that verify the authenticity and integrity of registration requests without requiring complex mutual authentication protocols during the registration itself, thus enhancing security while maintaining process simplicity
2Object-affected harmful factors
If integrity protection mechanisms are implemented for registration requests, then security against air interface threats is improved, but the processing overhead and message size increase
Solution Approach 1:
The patent extracts the integrity protection mechanism from the main registration message body by using separate MAC (Message Authentication Code) fields. This allows the registration request to maintain its core functionality with minimal size increase, as only compact cryptographic authentication data is added rather than embedding complex security protocols within the message structure
Solution Approach 2:
The patent employs parameter changes by using efficient cryptographic parameters such as truncated MACs and selective integrity protection only for critical message elements. This approach changes the security parameter implementation from protecting entire messages to protecting only essential registration data, thereby reducing the overall message size while maintaining adequate security against man-in-the-middle attacks
3Loss of time
If the source MME authenticates the UE on behalf of the target AMF, then authentication speed is improved, but the security context management becomes more complex
Solution Approach 1:
The patent applies preliminary action by having the source MME pre-validate the UE's security context and pre-establish trust relationships with the target AMF before the actual authentication occurs. This allows the MME to perform rapid authentication on behalf of the AMF during mobility events, as the security verification work has been prepared in advance
Solution Approach 2:
The patent implements self-service by enabling the source MME to autonomously authenticate the UE using its own stored security contexts without requiring real-time intervention from the target AMF. The MME independently verifies authentication credentials and makes authentication decisions, reducing authentication time while the complexity is managed through standardized security context formats and automatic context transfer protocols
Data Source
AI summary
A method for operating a User Equipment (UE) is disclosed, wherein the UE is served by a source first network function in a first network and requires to register with a target second network function in a second network. The method comprises generating a registration request with integrity protection for at least a part of the registration request, and sending an integrity protected part of the registration request to the source first network function via the target second network function.


