NAS Security Context Segmentation for 5G Replay Attack Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G systems, the use of multiple NAS connection links between terminals and AMF nodes via both 3GPP and non-3GPP access technologies leads to security vulnerabilities, particularly replay attacks due to inconsistent NAS COUNTs, compromising data security.

Innovation Solution

Implementing a security protection method where terminals and core network devices maintain separate NAS COUNTs for each access technology, using a first parameter to indicate the access technology during encryption and decryption processes, ensuring distinct security protection results even with shared NAS keys, thereby preventing replay attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a terminal uses one set of NAS keys and one set of NAS COUNTs to protect multiple NAS connection links, then the device complexity is reduced, but security reliability deteriorates due to replay attacks

Engineering Contradiction:
Improvesecurity context management complexityVSAvoiddata security reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the security protection mechanism by introducing a first parameter that distinguishes different NAS connection links. Instead of using a single unified NAS COUNT for all links, the system now maintains separate security contexts for each link identified by the first parameter. This segmentation allows the terminal to separately manage NAS COUNTs for different access technologies (3GPP and non-3GPP), preventing replay attacks while maintaining manageable complexity through structured organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by making security parameters specific to each NAS connection link rather than uniform across all links. The first parameter serves as a local identifier that tailors the security protection (NAS COUNT, encryption, integrity protection) to the specific characteristics of each connection link. This ensures that security measures are appropriately customized for each access technology and connection scenario.

Inventive Principle:
Principle #3Local quality

2Reliability

If separate NAS COUNTs are maintained for each access technology, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvedata security reliabilityVSAvoidsecurity context management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent achieves universality by designing a unified security framework that handles multiple NAS connection links through a common mechanism. The first parameter acts as a universal identifier that works across different access technologies (3GPP and non-3GPP), allowing the same security protection logic to be applied universally. This multi-functional approach enables the system to manage diverse connection types without requiring completely separate security mechanisms for each, thereby controlling complexity while maintaining high security reliability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP4114063B1Security protection method and apparatus
Publication Date: 2025.03.26 HUAWEI TECH CO LTD
  • EP4114063B1 patent drawingFigure 1
  • EP4114063B1 patent drawingFigure 2
  • EP4114063B1 patent drawingFigure 3~5

AI summary

This application relates to the field of wireless communications technologies. Embodiments of this application provide a security protection method and an apparatus, to implement security protection for a plurality of NAS connection links. The method in this application includes: determining, by a terminal, a first parameter, where the first parameter is used to indicate an access technology used to transmit a non-access stratum NAS message, and the terminal can support at least two access technologies, and can separately maintain a corresponding NAS count for each of the at least two access technologies; and then performing, by the terminal, security protection on the NAS message based on the first parameter, a NAS key, and a NAS count corresponding to an access technology used to transmit the NAS message. This application is applicable to a process of performing security protection on a NAS message.