Non-Public Network Access Signaling Without Identity Exposure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The RRC setup complete message in network sharing scenarios is not encrypted, exposing the identity of the CAG network accessed by a terminal device, leading to a security risk.
Innovation Solution
A communication method that generates and sends first indication information to indicate a plurality of non-public networks, including a first non-public network, where the specific network cannot be determined by the content of the indication information, ensuring network security by obscuring the identity of the accessed network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the terminal device reports the CAG network identity through the RRC setup complete message, then the base station can learn the connection status and allocate resources properly, but the unencrypted message exposes the network identity to interception and security risks
Solution Approach 1:
The patent segments the network identity information into multiple possible values (first non-public network, second non-public network, third non-public network) and uses indication information to point to one of them without directly revealing the specific identity. This segmentation allows the base station to understand connection status while preventing interception of the actual network identity.
Solution Approach 2:
The patent introduces an intermediary mechanism where the indication information acts as a reference or pointer rather than directly conveying the network identity. The base station uses this intermediary indication to determine connection status without the intercepted message revealing the actual network identity, thus mediating between the need for status reporting and security protection.
2Object-affected harmful factors
If the RRC setup complete message is encrypted to protect security, then the network identity cannot be intercepted, but the base station cannot efficiently determine the connection status for resource allocation
Solution Approach 1:
The patent segments the network identity into multiple possible options and uses compact indication information to represent which option is selected. This segmented approach allows efficient processing by the base station (high productivity) while the indication mechanism itself provides security protection by not directly exposing the full network identity.
Solution Approach 2:
The patent changes the parameter representation from direct network identity to an indirect indication value. This parameter transformation maintains security protection while enabling efficient base station processing, as the base station can quickly interpret the indication to determine connection status without handling sensitive identity data directly.
3Measurement precision
If the terminal device reports specific network identity, then the base station can accurately track connection status, but the user identity is exposed and network use security is compromised
Solution Approach 1:
The patent segments the network identity information into multiple discrete options (first, second, third non-public networks) and uses indication information to select one. This segmentation provides measurement precision for connection status tracking while preventing loss of user identity information, as the indication points to a network category rather than revealing specific user identity.
Solution Approach 2:
The indication information serves as an intermediary that enables accurate connection status tracking without directly exposing user identity. The base station can precisely determine which network type is accessed through this intermediary mechanism while the actual user identity remains protected from interception.
Data Source
AI summary
This application provides a communication method, a communications apparatus, and a communications system. The method includes: A terminal device generates first indication information, where the first indication information is used to indicate a plurality of non-public networks, the plurality of non-public networks include a first non-public network, and the first non-public network is a network that the terminal device requests to access; and the terminal device sends the first indication information to an access network device.


