Multi-NAS Container Delivery via Single Access Stratum Messaging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In distributed non-access stratum (NAS) architecture, multiple upper layer messages need to be securely transmitted between user equipment (UE) and multiple network functions (NFs) using a single lower layer message, requiring independent security termination and routing for each container.

Innovation Solution

The method involves encrypting multiple NAS payloads with specific encryption keys for different network functions, generating a message with temporary identifiers for routing, and transmitting this message to an apparatus that forwards or stores containers based on these identifiers, ensuring secure and efficient delivery.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If multiple NAS containers are transmitted via a single access stratum message, then transmission efficiency is improved, but security management complexity increases

Engineering Contradiction:
Improvetransmission efficiencyVSAvoidsecurity management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the single access stratum message into multiple distinct NAS containers, each with its own encryption key and security context. This allows independent security management for each container while maintaining efficient bundled transmission, resolving the contradiction between transmission efficiency and security management complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary security context identifier within each NAS container that mediates between the unified transmission structure and individual security requirements. This intermediary element enables the receiving end to properly manage security for each container without compromising the efficiency of bundled transmission.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If independent encryption is applied to each NAS payload, then security is improved, but processing overhead increases

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary encryption to each NAS payload before containerization, ensuring security is established in advance. This preliminary action allows the receiving end to process multiple containers more efficiently by having security already applied, reducing overall processing overhead while maintaining strong security.

Inventive Principle:
Principle #10Preliminary action

3Quantity of substance

If multiple NAS containers are bundled in a single message, then message overhead is reduced, but routing complexity increases

Engineering Contradiction:
Improvemessage overheadVSAvoidrouting complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent applies local quality by including specific routing information and security context identifiers within each individual NAS container. This allows the receiving end to route each container independently based on its local quality markers, reducing overall routing complexity while maintaining efficient bundled transmission.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250301311A1Method and apparatus to deliver multiple NAS containers via a single access stratum message
Publication Date: 2025.09.25 NOKIA TECHNOLOGIES OY
  • US20250301311A1 patent drawing
  • US20250301311A1 patent drawing
  • US20250301311A1 patent drawing

AI summary

A method includes receiving, at an AS layer of a user equipment (UE), a plurality of NAS payloads, wherein a first NAS payload is received from a first NAS sublayer and a subsequent payload is received from a subsequent NAS sublayer, encrypting, by the UE, the first payload with a first encryption generating a first encrypted payload and the subsequent payload with a subsequent encryption generating a subsequent encrypted payload, wherein the first encryption is associated with a first network function and the subsequent encryption is associated with a subsequent network function, generating, by the UE, a first message that includes a first temporary identifier including of routing information for the first network function and a first container, and a subsequent container, wherein the first container includes the first encrypted payload and the subsequent container includes the subsequent encrypted payload, and transmitting the first message to a first apparatus.