NAS Connection Identification for 5G Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 5G wireless communication systems, managing parallel Non-Access Stratum (NAS) connections across different access technologies, such as 3GPP and non-3GPP access nodes, poses challenges due to unreliable in-order delivery of NAS messages, which affects security and concurrency in legacy systems.
Innovation Solution
The method involves establishing and managing multiple NAS connections with unique identifiers (NAS CIDs) for each access type, ensuring integrity protection and confidentiality through shared master keys, allowing parallel execution of NAS procedures while maintaining cryptographic separation using NAS Connection Identification (NAS CONN ID) for each connection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple NAS connections are established across different access nodes, then connectivity and access flexibility are improved, but message delivery order reliability deteriorates
Solution Approach 1:
The patent segments the NAS message delivery mechanism by introducing connection-specific sequence counters (NAS COUNT values) for each NAS connection. This segmentation allows independent tracking of message order per connection, resolving the reliability issue while maintaining multi-access flexibility. Each connection maintains its own sequence state, preventing interleaved message confusion across different access nodes.
Solution Approach 2:
The patent adds a new dimension to NAS message tracking by introducing connection identifiers (NAS CID) alongside sequence counters. This dimensional extension allows the system to track messages not just by sequence number but by (connection_id, sequence_number) pairs, enabling reliable ordered delivery across multiple parallel connections without compromising access flexibility.
2Reliability
If separate security contexts are maintained for each NAS connection, then security integrity is improved, but system complexity increases
Solution Approach 1:
The patent merges the security context management by using a single master key (KAMF) to derive connection-specific integrity and encryption keys for each NAS connection. This combining approach maintains strong security isolation per connection while avoiding the complexity of completely separate security contexts, achieving security integrity with manageable system complexity.
Solution Approach 2:
The patent applies local quality by deriving unique integrity keys (KNASint) and encryption keys (KNASenc) specifically for each NAS connection from the master key. Each connection receives customized security parameters tailored to its specific needs, maintaining high security integrity while using a unified key derivation mechanism to control overall complexity.
3Device complexity
If legacy security mechanisms are used, then implementation simplicity is maintained, but replay protection reliability deteriorates in multi-connection scenarios
Solution Approach 1:
The patent implements preliminary action by establishing connection-specific NAS COUNT values and integrity keys before any NAS message exchange begins on each connection. This pre-configuration of security parameters ensures that replay protection is actively in place from the start of each connection, preventing replay attacks while maintaining a relatively simple implementation that builds on legacy mechanisms.
Solution Approach 2:
The patent introduces connection identifiers (NAS CID) as an intermediary element that links the legacy security mechanism to the multi-connection reality. The NAS CID acts as a mediator that allows the existing integrity protection and replay detection mechanisms to be applied separately to each connection, improving replay protection reliability while keeping the overall system implementation simple by reusing existing security protocols.
Data Source
AI summary
A method at a UE may include providing a first NAS connection with a network node through a first access node, wherein a first NAS CID is associated with the first NAS connection. While providing the first NAS connection, a second NAS CID may be allocated for a second NAS connection with the network node through a second access node. A registration request message may be transmitted to the network node to request the second NAS connection, wherein transmitting the registration request message includes performing integrity protection for the registration request message using the second NAS CID. A security mode command message may be received from the network node, wherein the security mode command message corresponds to the registration request message. Responsive to receiving the security mode command message, a security mode complete message may be transmitted to the network node through the second access node.


