NAS Security Mechanism for M2M Signalling Overhead Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security mechanisms in cellular networks are not well-suited for machine-to-machine (M2M) applications, which involve small data traffic volumes, leading to increased signalling overhead and the risk of denial-of-service attacks from fake base stations, as they require authentication between devices and base stations, and existing acknowledgement mechanisms are inefficient for M2M services.
Innovation Solution
A lightweight security mechanism that uses a wireless communication device with a radio interface and a data transmission verification entity to exchange user data packets over a Non Access Stratum (NAS) signalling connection, allowing for selective requests and verifiable acknowledgements to confirm data delivery and authenticate the core network node, thereby reducing the need for security associations with base stations and minimizing signalling overhead.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional security mechanisms with authentication between devices and base stations are used, then security against fake base stations is improved, but signalling overhead increases and network load increases for M2M applications
Solution Approach 1:
The patent extracts the authentication function from the base station level and relocates it to the core network level. Devices authenticate directly with the core network via NAS signalling, eliminating the need for device-base station authentication. This removes the security association requirements at the radio access network level while maintaining security through core network verification of device identities.
Solution Approach 2:
The core network acts as an intermediary that verifies device identities and provides security guarantees without requiring base station involvement in authentication. The core network mediates between devices and the network infrastructure, providing security services through NAS signalling rather than through radio access network authentication mechanisms.
2Reliability
If integrity protected acknowledgements are sent for every packet, then security and reliability are improved, but signalling overhead increases significantly
Solution Approach 1:
The patent applies partial action by sending integrity protected acknowledgements selectively rather than for every packet. Acknowledgements are provided based on specific conditions such as mobility events, network decisions, or periodic intervals, rather than universally for all data packets. This reduces the volume of integrity protected signalling while maintaining adequate security coverage.
Solution Approach 2:
The system implements periodic acknowledgment mechanisms where integrity protected acknowledgements are sent at regular intervals or based on periodic triggers rather than continuously for every packet. This periodic approach maintains security verification while significantly reducing the frequency and volume of signalling messages.
3Device complexity
If M2M devices use NAS signalling for data transmission, then the need for security associations with base stations is reduced, but vulnerability to fake base station attacks increases
Solution Approach 1:
The patent extracts the authentication function from the base station level and relocates it to the core network level. Devices authenticate directly with the core network via NAS signalling, eliminating the need for device-base station authentication. This removes the security association requirements at the radio access network level while maintaining security through core network verification of device identities.
Solution Approach 2:
Devices perform self-authentication with the core network using their unique identities and credentials, without requiring base station-mediated authentication. The device independently verifies the core network's identity and establishes secure NAS signalling connections, making the authentication process self-contained and independent of base station security associations.
Data Source
Figure 1~2
Figure 3~4
Figure 5
AI summary
A wireless communication device for use in a cellular network. The device comprises a radio interface for enabling communication between the device and a base station of the cellular network over a radio link, and a transfer entity for exchanging user data packets with a core network node of said cellular network over a signalling connection within a Non Access Stratum, via said radio link. The device further comprises a data transmission verification entity for using a verifiable acknowledgement, received from said core network node over a signalling connection within a Non Access Stratum, to confirm delivery of a user data packet sent to the core network node over a signalling connection, the data transmission verification entity being configured to selectively include with a user data packet sent to said core network node across a signalling connection, a request to return to the device a verifiable acknowledgement for the sent user data packet.