NAS Key Handling for Direct 5G Core Function Messaging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The 5G communication system's architecture, where a base station is directly connected to an access and mobility management function (AMF) but not directly to other control plane core network functions, increases transmission latency, which is not suitable for latency-sensitive services like ultra-reliable low-latency communication (URLLC).

Innovation Solution

A non-access stratum (NAS) security mechanism is updated by generating multiple NAS keys associated with different network functions (NFs) to facilitate direct connections between a radio access network device and multiple CN NFs, enabling encryption/decryption and integrity protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the base station is directly connected to the AMF but not directly to other control plane CN NFs, then the network architecture maintains centralized control and security management, but the transmission latency increases which is not suitable for latency-sensitive services

Engineering Contradiction:
Improvecentralized control and security managementVSAvoidtransmission latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the centralized control function into multiple distributed control plane CN NFs that can be directly connected to the base station. Instead of all control functions passing through the AMF, specific control plane functions are distributed to separate NFs that establish direct connections with the base station, reducing transmission latency while maintaining security through the NAS key mechanism.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces the NAS key as an intermediary security mechanism that enables direct communication between the base station and control plane CN NFs without requiring all communications to route through the AMF. The NAS key provides the necessary security mediation, allowing latency reduction through direct connections while maintaining centralized security management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of time

If multiple CN NFs are directly connected to the base station, then transmission latency is reduced for latency-sensitive services, but the NAS security mechanism must be updated to manage multiple security contexts

Engineering Contradiction:
Improvetransmission latencyVSAvoidNAS security mechanism complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent segments the security context management by creating separate NAS security contexts for each control plane CN NF. Each direct connection to a CN NF has its own dedicated NAS key and security context, isolating the security management of each NF and allowing independent handling of security for each connection without affecting others.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the security mechanism parameters by extending the NAS security framework to support multiple NF-specific security contexts. Each CN NF is assigned unique security parameters including dedicated NAS keys, security algorithms, and context identifiers, transforming the single-context security model into a multi-context model that scales with the number of direct CN NF connections.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If the terminal device generates multiple NAS keys for different NFs, then direct connections with multiple CN NFs are enabled with proper security, but the terminal device's key management complexity increases

Engineering Contradiction:
Improvedirect connection capability with multiple CN NFsVSAvoidterminal device key management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal NAS key management mechanism in the terminal device that can handle multiple NF-specific keys through a single standardized interface. The terminal's security module is designed to generate, store, and manage multiple NAS keys (KNAS_AMF, KNAS_SMF, KNAS_PC F, etc.) using a unified key derivation function that takes the NAS root key and NF-specific identifiers as inputs, allowing the terminal to adapt to any number of direct CN NF connections without requiring separate management procedures for each key.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20260095759A1Non-access stratum message processing method and apparatus
Publication Date: 2026.04.02 HUAWEI TECH CO LTD
  • US20260095759A1 patent drawing
  • US20260095759A1 patent drawing
  • US20260095759A1 patent drawing

AI summary

A non-access stratum (NAS) message processing method and apparatus. The method includes: a terminal device generates a plurality of NAS keys, where at least two of the plurality of NAS keys are respectively associated with different NFs, and the plurality of NAS keys include a first NAS key for a first NF. The first NF generates a first NAS key, where the first NF is a non-anchor function. The terminal device processes a NAS message between the terminal device and the first NF based on the first NAS key generated by the terminal device. The first NF processes a NAS message between the first NF and the terminal device based on the first NAS key generated by the first NF.