5G NAS Message Protection for Cross-PLMN Registration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 5G communication systems, the current NAS message protection mechanisms fail to ensure secure data transmission when a User Equipment (UE) registers with a second Public Land Mobile Network (PLMN) with different regulatory requirements, leading to potential exposure of sensitive user information as the existing mechanisms do not adapt to local regulations and may not support the security context of the first PLMN.
Innovation Solution
The method involves sending a cleartext information element in the initial registration request to the second PLMN, determining the allowed NAS security context reuse, and using the received NAS ciphering method to encrypt non-cleartext information elements, ensuring compliance with local regulations and secure data transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the UE uses the NAS ciphering method of the first PLMN to cipher the initial NAS message when registering to the second PLMN, then the security context of the first PLMN is maintained, but the local regulatory requirements of the second PLMN region may not be complied with
Solution Approach 1:
The UE performs preliminary determination of whether to reuse the 5G NAS security context before actually sending the ciphered initial NAS message. This preliminary check allows the UE to assess compatibility with the second PLMN's regulatory requirements and security capabilities, and only proceed with ciphering using the first PLMN's context if both parties support it, thus preventing compliance issues before they occur.
Solution Approach 2:
The system dynamically adjusts the ciphering approach based on real-time conditions. The UE can switch between two modes: (1) using the first PLMN's 5G NAS security context if the second PLMN supports it, or (2) falling back to sending the initial NAS message in cleartext if the second PLMN does not support the security context. This dynamic adaptation ensures compliance with local regulations while maximizing security.
2Adaptability or versatility
If the UE sends the initial NAS message in cleartext to the second PLMN, then compliance with local regulations is achieved, but sensitive user information may be exposed
Solution Approach 1:
The UE performs a preliminary check to determine whether the second PLMN supports reusing the 5G NAS security context from the first PLMN before deciding to send cleartext messages. This preliminary determination prevents unnecessary use of cleartext transmission, thereby reducing the risk of sensitive data exposure while ensuring regulatory compliance only when absolutely necessary.
Solution Approach 2:
The 5G NAS security context acts as an intermediary mechanism that bridges the security requirements of the first PLMN and the regulatory requirements of the second PLMN. When the second PLMN supports it, the security context enables encrypted communication, protecting sensitive data while meeting local regulations. When unsupported, the system gracefully degrades to cleartext transmission as a last resort.
3Reliability
If the UE determines whether the second PLMN allows reuse of 5G NAS security context, then secure transmission is optimized, but additional signaling overhead is introduced
Solution Approach 1:
The UE performs a partial check by only determining whether the second PLMN allows reuse of the 5G NAS security context when necessary (i.e., when the UE intends to send sensitive information). This selective determination minimizes unnecessary signaling overhead while ensuring secure transmission is optimized when it matters most, balancing security requirements with signaling efficiency.
Data Source
AI summary
The present disclosure relates to a communication method and system for converging a 5th-Generation (5G) communication system for supporting higher data rates beyond a 4th-Generation (4G) system with a technology for Internet of Things (IoT). The present disclosure may be applied to intelligent services based on the 5G communication technology and the IoT-related technology, such as smart home, smart building, smart city, smart car, connected car, health care, digital education, smart retail, security and safety services. Accordingly the embodiments herein provides a method and system for ciphering of initial NAS message protection procedure. A UE is registered to a first PLMN and a first 5G NAS security context has been established. The UE selects a second PLMN. The UE sends Initial Registration procedure with only cleartext IE to the second PLMN. The second PLMN may initiate and perform authentication procedure. The second PLMN initiates NAS Security mode control procedure and sends a Security Mode Command message containing the selected NAS ciphering method to the UE. The UE sends entire the Registration Request message containing both cleartext IE(s) and non-cleartext IE(s) using the NAS ciphering method sent in the Security Mode Complete message. The second PLMN send Registration Accept message.


