Air Interface Security via NAS Key MAC for Terminals
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication technologies face challenges in ensuring the security of air interface information sent from terminals to base stations, particularly for terminals that cannot set up Access Stratum (AS) security, making them vulnerable to attacks.
Innovation Solution
The method involves determining a Message Authentication Code (MAC) value based on a Non-Access Stratum (NAS) security key between the terminal and the core network device, and using this MAC value to protect the air interface information, ensuring security even without AS security setup between the terminal and the base station.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If AS security is set up between terminal and base station, then air interface information security is protected, but terminals that cannot set up AS security become vulnerable to attacks
Solution Approach 1:
The patent introduces the core network device as an intermediary to perform integrity protection on air interface information. Instead of requiring direct AS security between terminal and base station, the terminal establishes NAS security with the core network device, which then verifies the integrity of air interface information sent to the base station. This mediator approach allows terminals that cannot set up AS security to still have their information protected.
Solution Approach 2:
The patent segments the security protection function into two parts: NAS security between terminal and core network device, and integrity verification at the base station through the core network device. This segmentation allows the security mechanism to work independently of AS security setup, enabling broader terminal compatibility while maintaining security.
2Reliability
If NAS security key is used for integrity protection, then terminals without AS security can be protected, but additional security key management is required
Solution Approach 1:
The patent makes the NAS security key serve multiple functions: it establishes NAS security for control plane communication and simultaneously provides the basis for integrity protection of air interface information. This multi-functionality eliminates the need for separate security mechanisms, reducing overall system complexity despite the added protection capability.
Solution Approach 2:
The terminal uses its own NAS security key, which it already possesses for NAS communication, to generate the integrity protection for air interface information. The terminal self-services its security needs by leveraging existing security infrastructure rather than requiring additional key management infrastructure.
Data Source
AI summary
Embodiments of this application disclose an air interface information security protection method and apparatus, to protect security performance of air interface information sent by a terminal to a base station. In an embodiment, a terminal determines a first message authentication code (MAC) value based on a security key and air interface information, where the security key is a non-access stratum (NAS) security key between the terminal and a core network device; and the terminal sends the air interface information and the first MAC value to a base station.


