NAS Security Mechanism for M2M Signalling Overhead Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security mechanisms in cellular networks are not well-suited for machine-to-machine (M2M) applications, which involve small data traffic volumes, leading to increased signalling overhead and the risk of denial-of-service attacks from fake base stations, as they require authentication between devices and base stations, and existing acknowledgement mechanisms are inefficient for M2M services.

Innovation Solution

A lightweight security mechanism that uses a wireless communication device with a radio interface and a data transmission verification entity to exchange user data packets over a Non Access Stratum (NAS) signalling connection, allowing for selective requests and verifiable acknowledgements to confirm data delivery and authenticate the core network node, thereby reducing the need for security associations with base stations and minimizing signalling overhead.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security mechanisms with authentication between devices and base stations are used, then security against fake base stations is improved, but signalling overhead increases and network load increases for M2M applications

Engineering Contradiction:
Improvesecurity against fake base stationsVSAvoidsignalling overhead
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts the authentication function from the base station level and relocates it to the core network level. Devices authenticate directly with the core network via NAS signalling, eliminating the need for device-base station authentication. This removes the security association requirements at the radio access network level while maintaining security through core network verification of device identities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The core network acts as an intermediary that verifies device identities and provides security guarantees without requiring base station involvement in authentication. The core network mediates between devices and the network infrastructure, providing security services through NAS signalling rather than through radio access network authentication mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If integrity protected acknowledgements are sent for every packet, then security and reliability are improved, but signalling overhead increases significantly

Engineering Contradiction:
Improvedata delivery confirmationVSAvoidsignalling overhead
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent applies partial action by sending integrity protected acknowledgements selectively rather than for every packet. Acknowledgements are provided based on specific conditions such as mobility events, network decisions, or periodic intervals, rather than universally for all data packets. This reduces the volume of integrity protected signalling while maintaining adequate security coverage.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system implements periodic acknowledgment mechanisms where integrity protected acknowledgements are sent at regular intervals or based on periodic triggers rather than continuously for every packet. This periodic approach maintains security verification while significantly reducing the frequency and volume of signalling messages.

Inventive Principle:
Principle #19Periodic action

3Device complexity

If M2M devices use NAS signalling for data transmission, then the need for security associations with base stations is reduced, but vulnerability to fake base station attacks increases

Engineering Contradiction:
Improvesecurity associationsVSAvoidfake base station attacks
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication function from the base station level and relocates it to the core network level. Devices authenticate directly with the core network via NAS signalling, eliminating the need for device-base station authentication. This removes the security association requirements at the radio access network level while maintaining security through core network verification of device identities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Devices perform self-authentication with the core network using their unique identities and credentials, without requiring base station-mediated authentication. The device independently verifies the core network's identity and establishes secure NAS signalling connections, making the authentication process self-contained and independent of base station security associations.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2705646B1Security mechanism for mobile users
Publication Date: 2018.01.03 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP2705646B1 patent drawingFigure 1~2
  • EP2705646B1 patent drawingFigure 3~4
  • EP2705646B1 patent drawingFigure 5

AI summary

A wireless communication device for use in a cellular network. The device comprises a radio interface for enabling communication between the device and a base station of the cellular network over a radio link, and a transfer entity for exchanging user data packets with a core network node of said cellular network over a signalling connection within a Non Access Stratum, via said radio link. The device further comprises a data transmission verification entity for using a verifiable acknowledgement, received from said core network node over a signalling connection within a Non Access Stratum, to confirm delivery of a user data packet sent to the core network node over a signalling connection, the data transmission verification entity being configured to selectively include with a user data packet sent to said core network node across a signalling connection, a request to return to the device a verifiable acknowledgement for the sent user data packet.