NGN Layer-3 Mobility User Plane Data Security Key

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Next Generation Network (NGN) mobility security solutions do not provide a technical scheme for protecting the security of user plane data between the NGN user and the NGN network side, making it inconvenient in practical applications.

Innovation Solution

A method and system that involves terminal and authentication server authentication to obtain a shared key material, generating a mobility data security key using this shared key material, and utilizing this key to protect layer-3 mobility user plane data through a mobility data transmission module, ensuring the legitimacy and security of user plane data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing NGN mobility security solutions are used, then signaling plane security is protected, but user plane data security is not protected

Engineering Contradiction:
Improveuser plane data securityVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security protection into two distinct parts: signaling plane security (already protected by existing mechanisms) and user plane data security (protected by the new mobility data security key). This segmentation allows the invention to address user plane data security without disrupting the existing signaling plane security architecture, thereby improving reliability while avoiding excessive complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The mobility data security key serves multiple functions: it protects user plane data during mobility sessions, validates data integrity, and ensures confidentiality. This multi-functionality allows a single security mechanism to address multiple security requirements, improving user plane data security without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If no user plane data protection scheme is implemented, then system complexity remains low, but practical application convenience deteriorates

Engineering Contradiction:
Improvepractical application convenienceVSAvoidsecurity protection mechanism complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The mobility data security key is generated in advance during the authentication phase, before user plane data transmission begins. This preliminary action ensures that security protection is already in place when data transmission starts, improving practical application convenience without adding complex runtime security mechanisms.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The terminal and network side autonomously generate the mobility data security key using the shared authentication material without requiring manual configuration or external key management infrastructure. This self-service approach improves ease of operation while keeping the security mechanism relatively simple.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8862867B2Method and system for protecting security of the third layer mobility user plane data in NGN
Publication Date: 2014.10.14 ZTE CORP
  • US8862867B2 patent drawing
  • US8862867B2 patent drawing
  • US8862867B2 patent drawing

AI summary

The disclosure discloses a method for protecting security of layer-3 mobility user plane data in Next Generation Network (NGN), includes: performing authentication by a terminal with an authentication server; after the authentication is passed, obtaining a shared key material by both the terminal and the authentication server; generating, by the terminal and the authentication server, a mobility data security key according to the shared key material; transmitting, by the authentication server, the generated mobility data security key to a mobility data transmission module; protecting security of the layer-3 mobility user plane data, by the terminal and the mobility data transmission module, by using the mobility data security key. The disclosure also discloses a system for protecting security of layer-3 mobility user plane data in NGN. By using the method and the system provided by the disclosure, the protection for security of user plane data between the NGN user and the NGN network side is realized, and the security of user plane data of the terminal in layer-3 mobility session is enhanced.