5G NAS Security Context Handling for Multi-Access UE

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G NAS security context handling protocols fail to differentiate between 3GPP and non-3GPP access types when a UE registers or deregisters from multiple Public Land Mobile Networks (PLMNs), leading to unnecessary security context invalidation and increased signaling load, power consumption, and security risks.

Innovation Solution

A method where the UE handles NAS security contexts of the same PLMN similarly across access types and handles contexts of different PLMNs independently, ensuring correct invalidation and validation of security contexts based on registration and deregistration events for each access type.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the UE marks both 3GPP and non-3GPP security contexts as invalid when registering to a PLMN over one access type, then security is maintained, but unnecessary signaling load and power consumption increase

Engineering Contradiction:
ImprovesecurityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent segments the security context handling by access type (3GPP and non-3GPP) and by PLMN. Each access type maintains independent security context validity status, allowing the UE to invalidate security contexts only for the specific access type and PLMN combination where registration occurs, rather than invalidating all security contexts across all access types.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by making the security context validity decision localized to the specific access type and PLMN combination. When a UE registers to a PLMN over 3GPP access, only the 3GPP security context for that PLMN is invalidated, while non-3GPP security contexts remain valid. This localized approach prevents unnecessary security context invalidation and reduces unnecessary signaling.

Inventive Principle:
Principle #3Local quality

2Reliability

If the UE marks both 3GPP and non-3GPP security contexts as invalid when registering to a PLMN over one access type, then security is maintained, but unnecessary signaling load increases

Engineering Contradiction:
ImprovesecurityVSAvoidsignaling load
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the security context handling by access type (3GPP and non-3GPP) and by PLMN. Each access type maintains independent security context validity status, allowing the UE to invalidate security contexts only for the specific access type and PLMN combination where registration occurs, rather than invalidating all security contexts across all access types.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by making the security context validity decision localized to the specific access type and PLMN combination. When a UE registers to a PLMN over 3GPP access, only the 3GPP security context for that PLMN is invalidated, while non-3GPP security contexts remain valid. This localized approach prevents unnecessary security context invalidation and reduces unnecessary signaling.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If the UE sends unprotected initial NAS messages due to incorrect security context invalidation, then registration can proceed, but security risks increase

Engineering Contradiction:
Improveregistration procedureVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the security context handling by access type (3GPP and non-3GPP) and by PLMN. Each access type maintains independent security context validity status, allowing the UE to invalidate security contexts only for the specific access type and PLMN combination where registration occurs, rather than invalidating all security contexts across all access types.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by making the security context validity decision localized to the specific access type and PLMN combination. When a UE registers to a PLMN over 3GPP access, only the 3GPP security context for that PLMN is invalidated, while non-3GPP security contexts remain valid. This localized approach prevents unnecessary security context invalidation and reduces unnecessary signaling.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20240389052A1Improvement for 5g NAS security context handling when UE supports both 3GPP and non-3GPP accesses
Publication Date: 2024.11.21 MEDIATEK SINGAPORE PTE LTD
  • US20240389052A1 patent drawing
  • US20240389052A1 patent drawing
  • US20240389052A1 patent drawing

AI summary

A method of handling of 5G NAS security context for UEs supporting multiple registrations to different PLMNs over both 3GPP and non-3GPP access types is proposed. The UE should handle the NAS security contexts of the same PLMN similarly, and should handle the NAS security contexts of different PLMNs for different access types independently. If the UE registers to a PLMN over 3GPP or non-3GPP then the security contexts of the PLMN for both 3GPP and non-3GPP are set invalid. If the UE has been registered in a PLMN over 3GPP or non-3GPP and has stored security context for the PLMN and is now deregistered from the PLMN over 3GPP or non-3GPP, the security context of the PLMN becomes valid for both access types.