NAS Connection Mapping Across Heterogeneous Access Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack the ability to manage multiple non-3GPP access networks with different NAS connection identifiers, leading to inefficiencies and potential security risks when additional access types are introduced in future releases, such as trusted WLAN and MuLteFire access.

Innovation Solution

A system and method for user equipment (UE) to manage multiple access networks by generating and updating a mapping table with access network types and NAS connection identifiers, allowing flexible registration and security context management across heterogeneous networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single NAS connection identifier is used for all non-3GPP access networks, then device complexity is reduced, but adaptability to future access network types deteriorates

Engineering Contradiction:
ImproveNAS connection identifier managementVSAvoidSupport for multiple access network types
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent applies universality by creating a mapping table that can accommodate multiple access network types (3GPP, non-3GPP, trusted WLAN, MuLteFire) through a unified management mechanism. The single NAS connection identifier is mapped to multiple access network types via the mapping table, allowing the system to serve multiple access technologies with a single identifier while maintaining adaptability to future network types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate NAS connections are established for each access network type, then security is improved, but device complexity increases

Engineering Contradiction:
ImproveSecurity context managementVSAvoidConnection management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple NAS connections into a single unified connection managed through a mapping table. Instead of maintaining separate NAS connections for each access network type, the system combines them under one NAS connection identifier, with the mapping table establishing the relationships between different access networks and the unified connection, thereby reducing device complexity while preserving security through the AMF's ability to manage multiple security contexts.

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If existing NAS security context is reused across access networks, then productivity is improved, but security risks increase

Engineering Contradiction:
ImproveSession establishment efficiencyVSAvoidSecurity authorization
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements feedback through the mapping table that provides the AMF with information about which access networks are associated with which NAS connections. This feedback mechanism allows the AMF to verify serving network authorization before reusing existing security contexts, ensuring that productivity gains from context reuse do not compromise security. The mapping table enables the system to check and confirm proper authorization before allowing security context sharing.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12563386B2Method and apparatus for security realization of connections over heterogeneous access networks
Publication Date: 2026.02.24 NOKIA TECHNOLOGIES OY
  • US12563386B2 patent drawing
  • US12563386B2 patent drawing
  • US12563386B2 patent drawing

AI summary

This application relates to session establishment by user equipment over a plurality of heterogenous access networks. In one aspect, the heterogenous access networks may include 3GPP and non-3GPP access networks (106). The non-3GPP access networks (106) may include one or more non-3GPP trusted access networks (108) or one or more non-3GPP, non-trusted access networks (110).