Multiple NAS Containers in a Single AS Message With Independent Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In distributed non-access stratum (NAS) architecture, securing multiple upper layer messages transmitted between user equipment (UE) and network functions (NFs) via a single lower layer message is challenging, requiring independent protection and encryption for each container.

Innovation Solution

The method involves encrypting multiple NAS payloads at the user equipment (UE) with function-specific encryption, generating a message containing temporary identifiers for routing, and transmitting this encrypted message to a network apparatus, which deciphers and routes the containers to the appropriate network functions based on routing information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If multiple NAS containers are transmitted via a single access stratum message, then transmission efficiency is improved, but security management complexity increases

Engineering Contradiction:
Improvetransmission efficiencyVSAvoidsecurity management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the single access stratum message into multiple distinct NAS containers, each with its own security context. Each container is independently encrypted and tagged with routing information, allowing the system to maintain multiple security contexts within a single transmission unit without compromising security management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary routing information element within each container that mediates between the transmission efficiency goal and security management complexity. This routing information enables the network to correctly distribute containers to appropriate network functions without requiring complex end-to-end security management across all containers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If independent encryption is applied to each NAS container, then security is improved, but processing overhead increases

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by assigning specific encryption algorithms and security parameters to each individual NAS container based on its content and destination. Rather than using a uniform encryption approach, each container receives tailored security treatment, improving overall security while optimizing processing resources for each container's specific requirements.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If multiple NAS containers are routed to different network functions, then functionality is improved, but routing complexity increases

Engineering Contradiction:
ImprovefunctionalityVSAvoidrouting complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by embedding routing information within each NAS container during the message creation phase. This pre-configured routing data enables network elements to automatically and independently route containers to the appropriate network functions without requiring complex real-time routing decisions or centralized routing control.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250301310A1Method and apparatus to deliver multiple NAS containers via a single access stratum message
Publication Date: 2025.09.25 NOKIA TECHNOLOGIES OY
  • US20250301310A1 patent drawing
  • US20250301310A1 patent drawing
  • US20250301310A1 patent drawing

AI summary

A method includes receiving, at an access stratum (AS) layer of a user equipment (UE), a plurality of NAS payloads, wherein a first NAS payload is received from a first NAS sublayer and a subsequent payload is received from a subsequent NAS sublayer. The UE encrypts the first payload with a first encryption and the subsequent payload with a subsequent encryption, wherein the first encryption is associated with a first network function and the subsequent encryption is associated with a subsequent network function, generates a first message that includes a first temporary identifier including routing information for a first network function and a first container, and a subsequent container, wherein the first container includes the first encrypted payload and a temporary identifier including routing information for a subsequent network function, and the second container includes the second encrypted payload, and transmits the first message to a first apparatus.