NAS Security Context Segmentation for 5G Replay Attack Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 5G systems, the use of multiple NAS connection links between terminals and AMF nodes via both 3GPP and non-3GPP access technologies leads to security vulnerabilities, particularly replay attacks due to inconsistent NAS COUNTs, compromising data security.
Innovation Solution
Implementing a security protection method where terminals and core network devices maintain separate NAS COUNTs for each access technology, using a first parameter to indicate the access technology during encryption and decryption processes, ensuring distinct security protection results even with shared NAS keys, thereby preventing replay attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a terminal uses one set of NAS keys and one set of NAS COUNTs to protect multiple NAS connection links, then the device complexity is reduced, but security reliability deteriorates due to replay attacks
Solution Approach 1:
The patent segments the security protection mechanism by introducing a first parameter that distinguishes different NAS connection links. Instead of using a single unified NAS COUNT for all links, the system now maintains separate security contexts for each link identified by the first parameter. This segmentation allows the terminal to separately manage NAS COUNTs for different access technologies (3GPP and non-3GPP), preventing replay attacks while maintaining manageable complexity through structured organization.
Solution Approach 2:
The patent applies local quality by making security parameters specific to each NAS connection link rather than uniform across all links. The first parameter serves as a local identifier that tailors the security protection (NAS COUNT, encryption, integrity protection) to the specific characteristics of each connection link. This ensures that security measures are appropriately customized for each access technology and connection scenario.
2Reliability
If separate NAS COUNTs are maintained for each access technology, then security reliability is improved, but device complexity increases
Solution Approach 1:
The patent achieves universality by designing a unified security framework that handles multiple NAS connection links through a common mechanism. The first parameter acts as a universal identifier that works across different access technologies (3GPP and non-3GPP), allowing the same security protection logic to be applied universally. This multi-functional approach enables the system to manage diverse connection types without requiring completely separate security mechanisms for each, thereby controlling complexity while maintaining high security reliability.
Data Source
Figure 1
Figure 2
Figure 3~5
AI summary
This application relates to the field of wireless communications technologies. Embodiments of this application provide a security protection method and an apparatus, to implement security protection for a plurality of NAS connection links. The method in this application includes: determining, by a terminal, a first parameter, where the first parameter is used to indicate an access technology used to transmit a non-access stratum NAS message, and the terminal can support at least two access technologies, and can separately maintain a corresponding NAS count for each of the at least two access technologies; and then performing, by the terminal, security protection on the NAS message based on the first parameter, a NAS key, and a NAS count corresponding to an access technology used to transmit the NAS message. This application is applicable to a process of performing security protection on a NAS message.