Intersystem Mobility Integrity Verification With Dual MAC Parameters
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In intersystem mobility scenarios, particularly between 4G and 5G networks, existing mechanisms lack a way for user equipment (UE) to send integrity verification parameters for both networks, leading to potential performance degradation due to the need for re-authentication when security contexts differ.
Innovation Solution
UE sends both 4G-MAC and 5G-MAC integrity verification parameters in initial NAS messages during mobility events, allowing the target network to verify integrity without re-authentication, or seek assistance from the source network if necessary.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the UE sends only a single integrity verification parameter (MAC) for the target network during mobility, then the message structure remains simple, but the target network cannot verify integrity when security contexts differ from the source network, leading to re-authentication and performance degradation
Solution Approach 1:
The integrity verification mechanism is segmented into two independent parts: a first MAC parameter for the source network and a second MAC parameter for the target network. This segmentation allows each network to independently verify integrity using its own security context without requiring a single complex verification mechanism that supports both networks simultaneously.
Solution Approach 2:
The mobility management element acts as an intermediary that receives both MAC parameters, attempts verification with the target network's security context first, and only involves the source network's security context if target verification fails. This intermediary approach enables seamless verification across network boundaries without requiring the UE to manage complex verification logic.
2Speed
If the target network performs integrity verification using its own security context, then verification speed is improved, but verification fails when the UE has not previously accessed the target network, requiring fallback to source network verification
Solution Approach 1:
The UE prepares both the first MAC parameter (source network) and the second MAC parameter (target network) in advance within the initial NAS message, before the target network attempts verification. This preliminary preparation ensures that both verification paths are available immediately, enabling fast verification when the target context matches and reliable fallback when it doesn't.
Solution Approach 2:
The system dynamically changes the verification parameter being used based on verification results. The target network first attempts verification using the second MAC parameter with its own security context. When this fails, the system transitions to using the first MAC parameter with the source network's security context, effectively changing the verification parameter to match the available security context.
3Reliability
If re-authentication is performed when security contexts differ between source and target networks, then security is maintained, but network performance degrades due to additional authentication overhead
Solution Approach 1:
The target network performs self-service verification by first attempting to verify the second MAC parameter using its own security context. This self-service approach succeeds in most cases where the UE has previously accessed the target network, eliminating the need for source network involvement and avoiding performance-degrading re-authentication procedures.
Solution Approach 2:
The mobility management element serves as an intermediary that coordinates between target and source networks. It first attempts verification with the target network's security context, and only involves the source network when necessary. This intermediary coordination minimizes the frequency and overhead of full re-authentication procedures while maintaining security assurance.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
In accordance with the occurrence of a mobility event whereby user equipment moves from accessing a source network to accessing a target network in a communication system environment, the user equipment sends a control plane message to the target network comprising an integrity verification parameter associated with the source network and an integrity verification parameter associated with the target network. By providing integrity verification parameters for both the source network and the target network in an initial message sent by the user equipment to the mobility management element of the target network, the mobility management element of the target network can verify the user equipment on its own or seek the assistance of the source network.