NAS Key Handling for Direct 5G Core Function Messaging
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The 5G communication system's architecture, where a base station is directly connected to an access and mobility management function (AMF) but not directly to other control plane core network functions, increases transmission latency, which is not suitable for latency-sensitive services like ultra-reliable low-latency communication (URLLC).
Innovation Solution
A non-access stratum (NAS) security mechanism is updated by generating multiple NAS keys associated with different network functions (NFs) to facilitate direct connections between a radio access network device and multiple CN NFs, enabling encryption/decryption and integrity protection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the base station is directly connected to the AMF but not directly to other control plane CN NFs, then the network architecture maintains centralized control and security management, but the transmission latency increases which is not suitable for latency-sensitive services
Solution Approach 1:
The patent segments the centralized control function into multiple distributed control plane CN NFs that can be directly connected to the base station. Instead of all control functions passing through the AMF, specific control plane functions are distributed to separate NFs that establish direct connections with the base station, reducing transmission latency while maintaining security through the NAS key mechanism.
Solution Approach 2:
The patent introduces the NAS key as an intermediary security mechanism that enables direct communication between the base station and control plane CN NFs without requiring all communications to route through the AMF. The NAS key provides the necessary security mediation, allowing latency reduction through direct connections while maintaining centralized security management.
2Loss of time
If multiple CN NFs are directly connected to the base station, then transmission latency is reduced for latency-sensitive services, but the NAS security mechanism must be updated to manage multiple security contexts
Solution Approach 1:
The patent segments the security context management by creating separate NAS security contexts for each control plane CN NF. Each direct connection to a CN NF has its own dedicated NAS key and security context, isolating the security management of each NF and allowing independent handling of security for each connection without affecting others.
Solution Approach 2:
The patent changes the security mechanism parameters by extending the NAS security framework to support multiple NF-specific security contexts. Each CN NF is assigned unique security parameters including dedicated NAS keys, security algorithms, and context identifiers, transforming the single-context security model into a multi-context model that scales with the number of direct CN NF connections.
3Adaptability or versatility
If the terminal device generates multiple NAS keys for different NFs, then direct connections with multiple CN NFs are enabled with proper security, but the terminal device's key management complexity increases
Solution Approach 1:
The patent implements a universal NAS key management mechanism in the terminal device that can handle multiple NF-specific keys through a single standardized interface. The terminal's security module is designed to generate, store, and manage multiple NAS keys (KNAS_AMF, KNAS_SMF, KNAS_PC F, etc.) using a unified key derivation function that takes the NAS root key and NF-specific identifiers as inputs, allowing the terminal to adapt to any number of direct CN NF connections without requiring separate management procedures for each key.
Data Source
AI summary
A non-access stratum (NAS) message processing method and apparatus. The method includes: a terminal device generates a plurality of NAS keys, where at least two of the plurality of NAS keys are respectively associated with different NFs, and the plurality of NAS keys include a first NAS key for a first NF. The first NF generates a first NAS key, where the first NF is a non-anchor function. The terminal device processes a NAS message between the terminal device and the first NF based on the first NAS key generated by the terminal device. The first NF processes a NAS message between the first NF and the terminal device based on the first NAS key generated by the first NF.


