Multiple NAS Containers in One Access-Stratum Message with Secure Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In distributed non-access stratum (NAS) architectures, securing multiple upper layer messages transmitted between user equipment (UE) and network functions (NFs) through a single lower layer message is challenging, requiring independent security termination and routing for each container.
Innovation Solution
A method involving a first apparatus receiving a message with routing information and encrypted NAS payloads for multiple network functions, and transmitting each container to the associated network function based on the routing information, ensuring secure and independent processing of each container.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If multiple NAS containers are transmitted through a single lower layer message, then message efficiency is improved, but security protection becomes more complex
Solution Approach 1:
The patent segments the security protection process by applying independent encryption and integrity protection to each NAS container within the single lower layer message. Each container is treated as a separate security unit, allowing efficient transmission while maintaining robust security through individual protection mechanisms.
2Reliability
If independent security termination is implemented for each container, then security reliability is improved, but routing complexity increases
Solution Approach 1:
The patent introduces routing information as an intermediary element that carries identification data for each NAS container. This intermediary enables the network to correctly route each container to its designated network function while maintaining independent security termination, effectively managing routing complexity through structured information exchange.
3Productivity
If multiple containers are processed in parallel, then processing efficiency is improved, but resource consumption increases
Solution Approach 1:
The patent implements partial parallel processing where multiple NAS containers are handled simultaneously to the extent possible within system constraints. The system processes containers in parallel when resources are available while maintaining the ability to handle them sequentially when necessary, optimizing the balance between processing efficiency and resource consumption.
Data Source
AI summary
A method includes receiving, by a first apparatus, a first message from a second apparatus, the first message including routing information associated with respective network functions of a plurality of network functions and a plurality of containers associated with the respective network functions of the plurality of network functions, wherein each container of the plurality of containers includes a respective encrypted non access stratum (NAS) payload, and transmitting, by the first apparatus, each container to the associated network function based upon the routing information for that network function.


