Intersystem Mobility Integrity Verification With Dual MAC Parameters

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In intersystem mobility scenarios, particularly between 4G and 5G networks, existing mechanisms lack a way for user equipment (UE) to send integrity verification parameters for both networks, leading to potential performance degradation due to the need for re-authentication when security contexts differ.

Innovation Solution

UE sends both 4G-MAC and 5G-MAC integrity verification parameters in initial NAS messages during mobility events, allowing the target network to verify integrity without re-authentication, or seek assistance from the source network if necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the UE sends only a single integrity verification parameter (MAC) for the target network during mobility, then the message structure remains simple, but the target network cannot verify integrity when security contexts differ from the source network, leading to re-authentication and performance degradation

Engineering Contradiction:
Improveintegrity verification reliabilityVSAvoidmessage structure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The integrity verification mechanism is segmented into two independent parts: a first MAC parameter for the source network and a second MAC parameter for the target network. This segmentation allows each network to independently verify integrity using its own security context without requiring a single complex verification mechanism that supports both networks simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The mobility management element acts as an intermediary that receives both MAC parameters, attempts verification with the target network's security context first, and only involves the source network's security context if target verification fails. This intermediary approach enables seamless verification across network boundaries without requiring the UE to manage complex verification logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If the target network performs integrity verification using its own security context, then verification speed is improved, but verification fails when the UE has not previously accessed the target network, requiring fallback to source network verification

Engineering Contradiction:
Improveverification speedVSAvoidverification success rate
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The UE prepares both the first MAC parameter (source network) and the second MAC parameter (target network) in advance within the initial NAS message, before the target network attempts verification. This preliminary preparation ensures that both verification paths are available immediately, enabling fast verification when the target context matches and reliable fallback when it doesn't.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically changes the verification parameter being used based on verification results. The target network first attempts verification using the second MAC parameter with its own security context. When this fails, the system transitions to using the first MAC parameter with the source network's security context, effectively changing the verification parameter to match the available security context.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If re-authentication is performed when security contexts differ between source and target networks, then security is maintained, but network performance degrades due to additional authentication overhead

Engineering Contradiction:
Improvesecurity assuranceVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The target network performs self-service verification by first attempting to verify the second MAC parameter using its own security context. This self-service approach succeeds in most cases where the UE has previously accessed the target network, eliminating the need for source network involvement and avoiding performance-degrading re-authentication procedures.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The mobility management element serves as an intermediary that coordinates between target and source networks. It first attempts verification with the target network's security context, and only involves the source network when necessary. This intermediary coordination minimizes the frequency and overhead of full re-authentication procedures while maintaining security assurance.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3462760B1Security and integrity in intersystem mobility
Publication Date: 2025.07.23 NOKIA TECHNOLOGIES OY
  • EP3462760B1 patent drawingFigure 1
  • EP3462760B1 patent drawingFigure 2
  • EP3462760B1 patent drawingFigure 3

AI summary

In accordance with the occurrence of a mobility event whereby user equipment moves from accessing a source network to accessing a target network in a communication system environment, the user equipment sends a control plane message to the target network comprising an integrity verification parameter associated with the source network and an integrity verification parameter associated with the target network. By providing integrity verification parameters for both the source network and the target network in an initial message sent by the user equipment to the mobility management element of the target network, the mobility management element of the target network can verify the user equipment on its own or seek the assistance of the source network.