NAS Security Context Setup for Distributed 5G Core Connections
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The current non-access stratum security connection establishment procedure is not applicable to the distributed non-access stratum architecture in 5G mobile communication systems, necessitating a new approach for secure communication between terminal devices and core network elements.
Innovation Solution
A method for establishing non-access stratum security connections in a distributed architecture, where terminal devices generate and utilize multiple security contexts for secure communication with different network elements, enhancing flexibility and security through context-based encryption and verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a distributed non-access stratum architecture is implemented to enable independent communication between terminal devices and different core network elements, then communication flexibility and independence are improved, but the applicability of existing non-access stratum security connection establishment procedures deteriorates
Solution Approach 1:
The patent segments the security connection establishment process by introducing separate security contexts for different network elements (AMF security context and other NF security context). This allows independent security management for each network element, enabling the terminal device to communicate with multiple core network elements simultaneously while maintaining appropriate security for each connection.
Solution Approach 2:
The patent applies preliminary action by establishing security contexts in advance during the initial security setup phase. The terminal device and network establish security contexts before actual communication with different network elements, so that when communication is needed, the security framework is already in place and ready for immediate use.
2Reliability
If multiple security contexts are generated for different network elements, then security protection coverage is improved, but the complexity of security context management increases
Solution Approach 1:
The patent implements universality by creating a unified security framework that handles multiple security contexts through consistent procedures. The same security establishment and activation procedures are used regardless of which network element is being accessed, making the system multi-functional while maintaining procedural simplicity.
Solution Approach 2:
The patent applies dynamics by enabling the terminal device to dynamically select and activate appropriate security contexts based on which network element it is communicating with. The security context management is flexible and adaptive, switching between different security contexts as needed rather than using a static single-context approach.
3Ease of operation
If a unified security connection establishment procedure is used for all core network elements, then procedural simplicity is improved, but the ability to provide element-specific security protection deteriorates
Solution Approach 1:
The patent segments security contexts into different types (AMF security context and other NF security context) with specific purposes. Each security context is tailored for communication with specific network elements, providing element-specific security protection while maintaining clear procedural boundaries.
Solution Approach 2:
The patent introduces the concept of security contexts as intermediaries between the terminal device and different network elements. These security contexts act as mediators that enable appropriate security protection for each network element type while allowing the terminal device to use consistent security procedures.
Data Source
AI summary
A communication method is provided, including: A terminal device receives a first message from a first network element through a first access network device, where the first message is used to activate security protection for a first non-access stratum connection between the terminal device and the first network element. The terminal device generates a first security context corresponding to the first non-access stratum connection in response to the first message. The terminal device sends, to a second network element through a second access network device, a first establishment request security-protected based on the first security context, where the first establishment request is used to request to establish a second non-access stratum connection between the terminal device and the second network element. A security connection establishment request is security-protected by using a generated security context, thereby improving security of establishing a non-access stratum connection.


