5G NAS Security Context Handling for Multi-Access UE
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 5G NAS security context handling protocols fail to differentiate between 3GPP and non-3GPP access types when a UE registers or deregisters from multiple Public Land Mobile Networks (PLMNs), leading to unnecessary security context invalidation and increased signaling load, power consumption, and security risks.
Innovation Solution
A method where the UE handles NAS security contexts of the same PLMN similarly across access types and handles contexts of different PLMNs independently, ensuring correct invalidation and validation of security contexts based on registration and deregistration events for each access type.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the UE marks both 3GPP and non-3GPP security contexts as invalid when registering to a PLMN over one access type, then security is maintained, but unnecessary signaling load and power consumption increase
Solution Approach 1:
The patent segments the security context handling by access type (3GPP and non-3GPP) and by PLMN. Each access type maintains independent security context validity status, allowing the UE to invalidate security contexts only for the specific access type and PLMN combination where registration occurs, rather than invalidating all security contexts across all access types.
Solution Approach 2:
The patent applies local quality by making the security context validity decision localized to the specific access type and PLMN combination. When a UE registers to a PLMN over 3GPP access, only the 3GPP security context for that PLMN is invalidated, while non-3GPP security contexts remain valid. This localized approach prevents unnecessary security context invalidation and reduces unnecessary signaling.
2Reliability
If the UE marks both 3GPP and non-3GPP security contexts as invalid when registering to a PLMN over one access type, then security is maintained, but unnecessary signaling load increases
Solution Approach 1:
The patent segments the security context handling by access type (3GPP and non-3GPP) and by PLMN. Each access type maintains independent security context validity status, allowing the UE to invalidate security contexts only for the specific access type and PLMN combination where registration occurs, rather than invalidating all security contexts across all access types.
Solution Approach 2:
The patent applies local quality by making the security context validity decision localized to the specific access type and PLMN combination. When a UE registers to a PLMN over 3GPP access, only the 3GPP security context for that PLMN is invalidated, while non-3GPP security contexts remain valid. This localized approach prevents unnecessary security context invalidation and reduces unnecessary signaling.
3Ease of operation
If the UE sends unprotected initial NAS messages due to incorrect security context invalidation, then registration can proceed, but security risks increase
Solution Approach 1:
The patent segments the security context handling by access type (3GPP and non-3GPP) and by PLMN. Each access type maintains independent security context validity status, allowing the UE to invalidate security contexts only for the specific access type and PLMN combination where registration occurs, rather than invalidating all security contexts across all access types.
Solution Approach 2:
The patent applies local quality by making the security context validity decision localized to the specific access type and PLMN combination. When a UE registers to a PLMN over 3GPP access, only the 3GPP security context for that PLMN is invalidated, while non-3GPP security contexts remain valid. This localized approach prevents unnecessary security context invalidation and reduces unnecessary signaling.
Data Source
AI summary
A method of handling of 5G NAS security context for UEs supporting multiple registrations to different PLMNs over both 3GPP and non-3GPP access types is proposed. The UE should handle the NAS security contexts of the same PLMN similarly, and should handle the NAS security contexts of different PLMNs for different access types independently. If the UE registers to a PLMN over 3GPP or non-3GPP then the security contexts of the PLMN for both 3GPP and non-3GPP are set invalid. If the UE has been registered in a PLMN over 3GPP or non-3GPP and has stored security context for the PLMN and is now deregistered from the PLMN over 3GPP or non-3GPP, the security context of the PLMN becomes valid for both access types.


