5G NAS Message Protection for Cross-PLMN Registration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G communication systems, the current NAS message protection mechanisms fail to ensure secure data transmission when a User Equipment (UE) registers with a second Public Land Mobile Network (PLMN) with different regulatory requirements, leading to potential exposure of sensitive user information as the existing mechanisms do not adapt to local regulations and may not support the security context of the first PLMN.

Innovation Solution

The method involves sending a cleartext information element in the initial registration request to the second PLMN, determining the allowed NAS security context reuse, and using the received NAS ciphering method to encrypt non-cleartext information elements, ensuring compliance with local regulations and secure data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the UE uses the NAS ciphering method of the first PLMN to cipher the initial NAS message when registering to the second PLMN, then the security context of the first PLMN is maintained, but the local regulatory requirements of the second PLMN region may not be complied with

Engineering Contradiction:
Improvesecurity context maintenanceVSAvoidcompliance with local regulations
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The UE performs preliminary determination of whether to reuse the 5G NAS security context before actually sending the ciphered initial NAS message. This preliminary check allows the UE to assess compatibility with the second PLMN's regulatory requirements and security capabilities, and only proceed with ciphering using the first PLMN's context if both parties support it, thus preventing compliance issues before they occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adjusts the ciphering approach based on real-time conditions. The UE can switch between two modes: (1) using the first PLMN's 5G NAS security context if the second PLMN supports it, or (2) falling back to sending the initial NAS message in cleartext if the second PLMN does not support the security context. This dynamic adaptation ensures compliance with local regulations while maximizing security.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If the UE sends the initial NAS message in cleartext to the second PLMN, then compliance with local regulations is achieved, but sensitive user information may be exposed

Engineering Contradiction:
Improvecompliance with local regulationsVSAvoidexposure of sensitive data
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The UE performs a preliminary check to determine whether the second PLMN supports reusing the 5G NAS security context from the first PLMN before deciding to send cleartext messages. This preliminary determination prevents unnecessary use of cleartext transmission, thereby reducing the risk of sensitive data exposure while ensuring regulatory compliance only when absolutely necessary.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The 5G NAS security context acts as an intermediary mechanism that bridges the security requirements of the first PLMN and the regulatory requirements of the second PLMN. When the second PLMN supports it, the security context enables encrypted communication, protecting sensitive data while meeting local regulations. When unsupported, the system gracefully degrades to cleartext transmission as a last resort.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the UE determines whether the second PLMN allows reuse of 5G NAS security context, then secure transmission is optimized, but additional signaling overhead is introduced

Engineering Contradiction:
Improvesecure data transmissionVSAvoidsignaling overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The UE performs a partial check by only determining whether the second PLMN allows reuse of the 5G NAS security context when necessary (i.e., when the UE intends to send sensitive information). This selective determination minimizes unnecessary signaling overhead while ensuring secure transmission is optimized when it matters most, balancing security requirements with signaling efficiency.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11785450B2Method and system for providing non-access stratum (NAS) message protection
Publication Date: 2023.10.10 SAMSUNG ELECTRONICS CO LTD
  • US11785450B2 patent drawing
  • US11785450B2 patent drawing
  • US11785450B2 patent drawing

AI summary

The present disclosure relates to a communication method and system for converging a 5th-Generation (5G) communication system for supporting higher data rates beyond a 4th-Generation (4G) system with a technology for Internet of Things (IoT). The present disclosure may be applied to intelligent services based on the 5G communication technology and the IoT-related technology, such as smart home, smart building, smart city, smart car, connected car, health care, digital education, smart retail, security and safety services. Accordingly the embodiments herein provides a method and system for ciphering of initial NAS message protection procedure. A UE is registered to a first PLMN and a first 5G NAS security context has been established. The UE selects a second PLMN. The UE sends Initial Registration procedure with only cleartext IE to the second PLMN. The second PLMN may initiate and perform authentication procedure. The second PLMN initiates NAS Security mode control procedure and sends a Security Mode Command message containing the selected NAS ciphering method to the UE. The UE sends entire the Registration Request message containing both cleartext IE(s) and non-cleartext IE(s) using the NAS ciphering method sent in the Security Mode Complete message. The second PLMN send Registration Accept message.