NGN Layer-3 Mobility User Plane Data Security Key
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Next Generation Network (NGN) mobility security solutions do not provide a technical scheme for protecting the security of user plane data between the NGN user and the NGN network side, making it inconvenient in practical applications.
Innovation Solution
A method and system that involves terminal and authentication server authentication to obtain a shared key material, generating a mobility data security key using this shared key material, and utilizing this key to protect layer-3 mobility user plane data through a mobility data transmission module, ensuring the legitimacy and security of user plane data transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing NGN mobility security solutions are used, then signaling plane security is protected, but user plane data security is not protected
Solution Approach 1:
The patent segments the security protection into two distinct parts: signaling plane security (already protected by existing mechanisms) and user plane data security (protected by the new mobility data security key). This segmentation allows the invention to address user plane data security without disrupting the existing signaling plane security architecture, thereby improving reliability while avoiding excessive complexity.
Solution Approach 2:
The mobility data security key serves multiple functions: it protects user plane data during mobility sessions, validates data integrity, and ensures confidentiality. This multi-functionality allows a single security mechanism to address multiple security requirements, improving user plane data security without proportionally increasing system complexity.
2Ease of operation
If no user plane data protection scheme is implemented, then system complexity remains low, but practical application convenience deteriorates
Solution Approach 1:
The mobility data security key is generated in advance during the authentication phase, before user plane data transmission begins. This preliminary action ensures that security protection is already in place when data transmission starts, improving practical application convenience without adding complex runtime security mechanisms.
Solution Approach 2:
The terminal and network side autonomously generate the mobility data security key using the shared authentication material without requiring manual configuration or external key management infrastructure. This self-service approach improves ease of operation while keeping the security mechanism relatively simple.
Data Source
AI summary
The disclosure discloses a method for protecting security of layer-3 mobility user plane data in Next Generation Network (NGN), includes: performing authentication by a terminal with an authentication server; after the authentication is passed, obtaining a shared key material by both the terminal and the authentication server; generating, by the terminal and the authentication server, a mobility data security key according to the shared key material; transmitting, by the authentication server, the generated mobility data security key to a mobility data transmission module; protecting security of the layer-3 mobility user plane data, by the terminal and the mobility data transmission module, by using the mobility data security key. The disclosure also discloses a system for protecting security of layer-3 mobility user plane data in NGN. By using the method and the system provided by the disclosure, the protection for security of user plane data between the NGN user and the NGN network side is realized, and the security of user plane data of the terminal in layer-3 mobility session is enhanced.


