Multiple NAS Containers in One Access-Stratum Message with Secure Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In distributed non-access stratum (NAS) architectures, securing multiple upper layer messages transmitted between user equipment (UE) and network functions (NFs) through a single lower layer message is challenging, requiring independent security termination and routing for each container.

Innovation Solution

A method involving a first apparatus receiving a message with routing information and encrypted NAS payloads for multiple network functions, and transmitting each container to the associated network function based on the routing information, ensuring secure and independent processing of each container.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If multiple NAS containers are transmitted through a single lower layer message, then message efficiency is improved, but security protection becomes more complex

Engineering Contradiction:
Improvemessage efficiencyVSAvoidsecurity protection complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the security protection process by applying independent encryption and integrity protection to each NAS container within the single lower layer message. Each container is treated as a separate security unit, allowing efficient transmission while maintaining robust security through individual protection mechanisms.

Inventive Principle:
Principle #1Segmentation

2Reliability

If independent security termination is implemented for each container, then security reliability is improved, but routing complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidrouting complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces routing information as an intermediary element that carries identification data for each NAS container. This intermediary enables the network to correctly route each container to its designated network function while maintaining independent security termination, effectively managing routing complexity through structured information exchange.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If multiple containers are processed in parallel, then processing efficiency is improved, but resource consumption increases

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidresource consumption
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The patent implements partial parallel processing where multiple NAS containers are handled simultaneously to the extent possible within system constraints. The system processes containers in parallel when resources are available while maintaining the ability to handle them sequentially when necessary, optimizing the balance between processing efficiency and resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250301399A1Method and apparatus to deliver multiple NAS containers via a single access stratum message
Publication Date: 2025.09.25 NOKIA TECHNOLOGIES OY
  • US20250301399A1 patent drawing
  • US20250301399A1 patent drawing
  • US20250301399A1 patent drawing

AI summary

A method includes receiving, by a first apparatus, a first message from a second apparatus, the first message including routing information associated with respective network functions of a plurality of network functions and a plurality of containers associated with the respective network functions of the plurality of network functions, wherein each container of the plurality of containers includes a respective encrypted non access stratum (NAS) payload, and transmitting, by the first apparatus, each container to the associated network function based upon the routing information for that network function.