NAS Message Security Parameters for User Plane Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge of enhancing security and reliability in wireless communication systems, particularly in 6G networks, necessitates the development of efficient security protocols to protect data transmission amidst the increased connectivity and complexity of devices and services.
Innovation Solution
A method and apparatus for data security in 4G, 5G, and 6G wireless communication systems involve a user equipment (UE) transmitting security protection parameters to a mobility management entity (MME) via a base station, with a policy charging function (PCF) determining a security policy and the MME sending an attach accept message with network capability parameters to support enhanced security protocols for user plane data protection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security protection parameters are transmitted and security policies are determined for user plane data protection, then data security and reliability are improved, but device complexity and protocol overhead increase
Solution Approach 1:
The security protection mechanism is segmented into distinct components: UE capability indication (support for user plane integrity protection and full rate protection), PCF policy determination, and MME security parameter configuration. This segmentation allows each component to be optimized independently while maintaining overall security.
Solution Approach 2:
The UE indicates its security protection capabilities in advance during the attach procedure, allowing the network to pre-determine appropriate security policies through the PCF and configure corresponding parameters before actual data transmission begins. This preliminary action prevents security issues during data transfer.
2Reliability
If enhanced security protocols are implemented with security protection parameters, then data transmission integrity is improved, but communication overhead and processing time increase
Solution Approach 1:
Security capabilities and policies are determined during the initial attach procedure rather than during each data transmission. The UE indicates its capabilities upfront, the PCF determines policies in advance, and the MME configures parameters before data transfer, eliminating repeated processing overhead.
Solution Approach 2:
The system uses self-service mechanisms where the UE autonomously indicates its security capabilities, the PCF autonomously determines appropriate policies based on those capabilities, and the MME autonomously configures security parameters, reducing the need for manual intervention and repeated negotiations.
3Reliability
If security protection for user plane is enabled with capability indication, then security coverage is improved, but message size and network signaling increase
Solution Approach 1:
The security protection mechanism applies different protection levels locally based on UE capabilities and network policies. The system supports both full rate user plane integrity protection and non-full rate protection, allowing selective application of security measures to different data flows or UEs based on their specific requirements.
Solution Approach 2:
The system dynamically changes security parameters (integrity protection enablement, full rate vs. non-full rate protection) based on UE capability indications and network policy determinations. These parameter changes allow flexible security coverage adjustment without fixed message overhead.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method, performed by a user equipment (UE), for protecting data includes: transmitting an attach request message including at least one security protection parameter regarding a UE capability to support a security protection for a user plane, to a mobility management entity (MME) via a base station; and in case that a security policy is determined at a policy charging function (PCF) based on the attach request message and information of the security policy is received at the MME, receiving an attach accept message including at least one security protection parameter regarding a network capability for the security policy related with an evolved packet system (EPS) bearer, from the MME via the base station.