Air Interface Security via NAS Key MAC for Terminals

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication technologies face challenges in ensuring the security of air interface information sent from terminals to base stations, particularly for terminals that cannot set up Access Stratum (AS) security, making them vulnerable to attacks.

Innovation Solution

The method involves determining a Message Authentication Code (MAC) value based on a Non-Access Stratum (NAS) security key between the terminal and the core network device, and using this MAC value to protect the air interface information, ensuring security even without AS security setup between the terminal and the base station.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If AS security is set up between terminal and base station, then air interface information security is protected, but terminals that cannot set up AS security become vulnerable to attacks

Engineering Contradiction:
Improveair interface information securityVSAvoidterminal compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces the core network device as an intermediary to perform integrity protection on air interface information. Instead of requiring direct AS security between terminal and base station, the terminal establishes NAS security with the core network device, which then verifies the integrity of air interface information sent to the base station. This mediator approach allows terminals that cannot set up AS security to still have their information protected.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the security protection function into two parts: NAS security between terminal and core network device, and integrity verification at the base station through the core network device. This segmentation allows the security mechanism to work independently of AS security setup, enabling broader terminal compatibility while maintaining security.

Inventive Principle:
Principle #1Segmentation

2Reliability

If NAS security key is used for integrity protection, then terminals without AS security can be protected, but additional security key management is required

Engineering Contradiction:
Improveair interface information securityVSAvoidsecurity key management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the NAS security key serve multiple functions: it establishes NAS security for control plane communication and simultaneously provides the basis for integrity protection of air interface information. This multi-functionality eliminates the need for separate security mechanisms, reducing overall system complexity despite the added protection capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The terminal uses its own NAS security key, which it already possesses for NAS communication, to generate the integrity protection for air interface information. The terminal self-services its security needs by leveraging existing security infrastructure rather than requiring additional key management infrastructure.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12089045B2Air interface information security protection method and apparatus
Publication Date: 2024.09.10 HUAWEI TECH CO LTD
  • US12089045B2 patent drawing
  • US12089045B2 patent drawing
  • US12089045B2 patent drawing

AI summary

Embodiments of this application disclose an air interface information security protection method and apparatus, to protect security performance of air interface information sent by a terminal to a base station. In an embodiment, a terminal determines a first message authentication code (MAC) value based on a security key and air interface information, where the security key is a non-access stratum (NAS) security key between the terminal and a core network device; and the terminal sends the air interface information and the first MAC value to a base station.