Initial NAS Message Segmentation for 5G Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 5G NR technology, the 3GPP specifications do not clearly distinguish between cleartext and ciphered Information Elements (IEs) in initial Non-Access Stratum (NAS) messages, making it difficult to identify and protect the required IEs for security establishment between User Equipment (UE) and the service network.
Innovation Solution
The proposed solution involves sending an initial NAS message with a limited set of IEs in cleartext and a container IE carrying the NAS message Protocol Data Unit (PDU) ciphered with the NAS security context, allowing clear differentiation between cleartext and ciphered data, and introducing new message types such as 'Partially ciphered 5GS NAS message' and 'Integrity protected and partially ciphered' security headers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If an initial NAS message is sent in a partially protected format with some IEs in cleartext and others ciphered, then security establishment between UE and service network is enabled, but it becomes difficult to identify whether an IE is cleartext or ciphered when optional IEs are included
Solution Approach 1:
The NAS message is segmented into distinct cleartext IEs and ciphered IEs with clear delimiters. Each IE is explicitly marked with its protection status through structured formatting, allowing the network to reliably identify which IEs are in cleartext and which are ciphered, even when optional IEs are present.
Solution Approach 2:
A container IE is introduced as an intermediary structure that carries the initial NAS message PDU in a clearly marked ciphered format. This container acts as a mediator that separates the cleartext IEs from the ciphered IEs, making it unambiguous to the network which parts require decryption and which can be processed directly.
2Adaptability or versatility
If optional cleartext IEs are located in the middle of optional ciphered IEs, then flexibility in message composition is achieved, but recognition of cleartext vs ciphered IEs becomes even more difficult
Solution Approach 1:
Each IE is individually segmented and marked with explicit indicators of its protection status. The message structure uses clear delimiters and markers before each IE to indicate whether it is cleartext or ciphered, maintaining flexibility in IE selection and ordering while ensuring unambiguous identification of protection status.
Solution Approach 2:
The patent uses metaphorical 'color coding' through explicit markers and indicators that visually (in the data structure sense) distinguish cleartext IEs from ciphered IEs. Each IE carries metadata or markers that clearly indicate its protection status, making it immediately recognizable regardless of position in the message.
Data Source
AI summary
A User Equipment (UE) including a wireless transceiver and a controller is provided. The wireless transceiver performs wireless transmission and reception to and from a service network. The controller transitions the UE from a Radio Resource Control (RRC) idle state to an RRC connected state, and after transitioning the UE from the RRC idle state to the RRC connected state, sends an initial Non-Access Stratum (NAS) message comprising a limited set of Information Elements (IEs) in cleartext, which are required to establish security between the UE and the service network, and a container IE carrying an initial NAS message Protocol Data Unit (PDU) ciphered with NAS security context to the service network via the wireless transceiver.


