NAS Security Context Setup for Distributed 5G Core Connections

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The current non-access stratum security connection establishment procedure is not applicable to the distributed non-access stratum architecture in 5G mobile communication systems, necessitating a new approach for secure communication between terminal devices and core network elements.

Innovation Solution

A method for establishing non-access stratum security connections in a distributed architecture, where terminal devices generate and utilize multiple security contexts for secure communication with different network elements, enhancing flexibility and security through context-based encryption and verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a distributed non-access stratum architecture is implemented to enable independent communication between terminal devices and different core network elements, then communication flexibility and independence are improved, but the applicability of existing non-access stratum security connection establishment procedures deteriorates

Engineering Contradiction:
Improvecommunication flexibilityVSAvoidsecurity connection establishment complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the security connection establishment process by introducing separate security contexts for different network elements (AMF security context and other NF security context). This allows independent security management for each network element, enabling the terminal device to communicate with multiple core network elements simultaneously while maintaining appropriate security for each connection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies preliminary action by establishing security contexts in advance during the initial security setup phase. The terminal device and network establish security contexts before actual communication with different network elements, so that when communication is needed, the security framework is already in place and ready for immediate use.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple security contexts are generated for different network elements, then security protection coverage is improved, but the complexity of security context management increases

Engineering Contradiction:
Improvesecurity protection coverageVSAvoidsecurity context management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements universality by creating a unified security framework that handles multiple security contexts through consistent procedures. The same security establishment and activation procedures are used regardless of which network element is being accessed, making the system multi-functional while maintaining procedural simplicity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent applies dynamics by enabling the terminal device to dynamically select and activate appropriate security contexts based on which network element it is communicating with. The security context management is flexible and adaptive, switching between different security contexts as needed rather than using a static single-context approach.

Inventive Principle:
Principle #15Dynamics

3Ease of operation

If a unified security connection establishment procedure is used for all core network elements, then procedural simplicity is improved, but the ability to provide element-specific security protection deteriorates

Engineering Contradiction:
Improveprocedural simplicityVSAvoidelement-specific security protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments security contexts into different types (AMF security context and other NF security context) with specific purposes. Each security context is tailored for communication with specific network elements, providing element-specific security protection while maintaining clear procedural boundaries.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces the concept of security contexts as intermediaries between the terminal device and different network elements. These security contexts act as mediators that enable appropriate security protection for each network element type while allowing the terminal device to use consistent security procedures.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250365578A1Communication method and communication apparatus
Publication Date: 2025.11.27 HUAWEI TECH CO LTD
  • US20250365578A1 patent drawing
  • US20250365578A1 patent drawing
  • US20250365578A1 patent drawing

AI summary

A communication method is provided, including: A terminal device receives a first message from a first network element through a first access network device, where the first message is used to activate security protection for a first non-access stratum connection between the terminal device and the first network element. The terminal device generates a first security context corresponding to the first non-access stratum connection in response to the first message. The terminal device sends, to a second network element through a second access network device, a first establishment request security-protected based on the first security context, where the first establishment request is used to request to establish a second non-access stratum connection between the terminal device and the second network element. A security connection establishment request is security-protected by using a generated security context, thereby improving security of establishing a non-access stratum connection.