Security Protected NAS Protocol for Mobile Telecommunication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current NAS protocols in mobile communication systems, such as 3GPP EPS, lack mature definitions for mobility, location, and registration management procedures, leading to unclear issues and malfunctions, particularly in terms of security protection and role definitions between UE and MME.

Innovation Solution

A method is introduced to support mobility, location, and registration management using security-protected NAS messages between UE and MME, involving state transition requests, key generation, and authentication processes to ensure efficient handover, location updates, and registration, even across different radio access technologies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If NAS protocols are used for mobility and registration management in 3GPP EPS, then communication functions are enabled, but security protection and procedure definitions are insufficient leading to malfunctions

Engineering Contradiction:
Improvesecurity protectionVSAvoidprocedure definition complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by performing security context transfer from the old MME to the new MME before the UE actually moves to the new MME. The old MME stores and forwards the security context (including keys and algorithms) in advance, so that when handover occurs, the new MME already has the necessary security information to protect NAS messages, eliminating the need for re-authentication and ensuring continuous security protection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses the old MME as an intermediary to transfer security context to the new MME. The old MME acts as a mediator that collects the security context from the UE and forwards it to the new MME during handover preparation, ensuring that security protection is maintained without requiring direct UE involvement in the key transfer process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security context is transferred during handover, then security protection is maintained, but signaling overhead increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidsignaling overhead
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges the security context transfer process with the existing handover signaling流程. Instead of creating separate signaling messages for security context transfer, the patent incorporates the security context information into the existing handover request and response messages between MMEs, thereby transferring security context without increasing overall signaling overhead.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent uses copying by creating a copy of the security context (keys, algorithms, and related parameters) from the old MME and transferring it to the new MME. This copying approach allows the new MME to independently process NAS messages with the same security protection without requiring continuous communication with the old MME or UE, reducing ongoing signaling overhead.

Inventive Principle:
Principle #26Copying

3Reliability

If NAS messages are protected with security context, then message integrity is ensured, but message processing complexity increases

Engineering Contradiction:
Improvemessage integrityVSAvoidmessage processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-configuring the new MME with the complete security context (including encryption keys, integrity protection keys, and algorithm identifiers) before NAS message processing begins. This allows the new MME to immediately apply the correct security protection to incoming NAS messages without needing to query the old MME or perform complex key derivation during message processing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses parameter changes by dynamically selecting and applying different security algorithms (encryption and integrity protection algorithms) based on the transferred security context parameters. The new MME changes its processing parameters to match the UE's capabilities and the network's security policy, ensuring message integrity while adapting to different security requirements.

Inventive Principle:
Principle #35Parameter changes

4Adaptability or versatility

If handover between MMEs is supported, then mobility management is improved, but key management complexity increases

Engineering Contradiction:
Improvemobility managementVSAvoidkey management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent uses the old MME as an intermediary to manage key transfer during handover. The old MME collects the security context from the UE and forwards it to the new MME, acting as a mediator that simplifies key management for both the UE and the new MME. This intermediary approach allows seamless handover without requiring the UE to directly manage keys across multiple MMEs.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies copying by creating a copy of the security context (including all necessary keys and parameters) and transferring it from the old MME to the new MME. This copying mechanism ensures that the new MME has an independent copy of the security context, eliminating the need for complex key synchronization mechanisms between multiple MMEs and simplifying key management during handover.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8638936B2Security protected non-access stratum protocol operation supporting method in a mobile telecommunication system
Publication Date: 2014.01.28 SAMSUNG ELECTRONICS CO LTD
  • US8638936B2 patent drawing
  • US8638936B2 patent drawing
  • US8638936B2 patent drawing

AI summary

The present invention relates to a method and system for the management of the mobility, the management of an idle mode, the registration management (management of attachment and detachment), and the location management (management of tracking area) of a terminal by using a non-access stratum (i.e., network stratum, hereinafter referred to as “NAS”) in a mobile telecommunication network. To this end, the method for the management of mobility, the management of an idle mode, the registration management, and the location management of a terminal by using a NAS protocol, i.e., messages, according to an embodiment of the present invention, includes a terminal (hereinafter, referred to as “UE”) and a mobility management entity (hereinafter, referred to as “MME”), and addresses to a method for efficiently processing security protected NAS messages if received messages are security protected NAS messages, in a case of sending or receiving messages serving as EMM (EPS Mobility Management) messages, i.e., mobility management messages, in a network such as an EPS (Evolved Packet System) of 3GPP, when the terminal performs handover in an active mode, performs location management in an idle mode, and registers to a network, thereby achieving improved efficiency in the mobility management, the position management, and the registration management of a terminal.