5G NSSAI Encryption via AS Security Context
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The 5G system's inability to securely send Network Slice Selection Assistance Information (NSSAI) in clear text raises security concerns, leading to potential network congestion and inefficient resource allocation, as the AMF may become overwhelmed and signaling overhead increases due to incorrect AMF selection and resource allocation issues.
Innovation Solution
A mobile communication system that encrypts NSSAI using an Access Stratum (AS) security context, allowing secure transmission and decryption by User Equipment (UE) and Radio Access Network (RAN) nodes, ensuring secure NSSAI exchange and preventing network congestion.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If NSSAI is transmitted in clear text in RRC layer, then transmission simplicity is improved, but user privacy and security are compromised
Solution Approach 1:
The patent introduces an intermediary encryption mechanism using AS security context between UE and RAN. The NSSAI information is encrypted using AS security context before transmission in RRC messages, and decrypted by RAN using the same AS security context. This intermediary encryption layer protects user privacy while maintaining the efficiency of RRC layer transmission.
2Reliability
If NSSAI is encrypted using AS security context, then user privacy is protected, but transmission complexity increases
Solution Approach 1:
The patent implements self-service encryption where both UE and RAN possess the AS security context and can independently perform encryption and decryption operations. The UE encrypts NSSAI using its AS security context before transmission, and RAN decrypts using its own AS security context upon reception. This self-service approach distributes the cryptographic burden and simplifies the overall system architecture.
3Productivity
If correct AMF selection is enabled through NSSAI transmission, then network resource allocation efficiency is improved, but signaling overhead increases due to security procedures
Solution Approach 1:
The patent applies preliminary action by establishing AS security context before NSSAI transmission occurs. The security context is set up in advance during initial connection establishment, enabling subsequent encrypted NSSAI transmissions without repeated security setup procedures. This preliminary security establishment reduces signaling overhead in later communications while ensuring correct AMF selection through secure NSSAI delivery.
Data Source
AI summary
This disclosure defines a procedure to security protection to sensitive information in AS layer during AS connection establishment procedure. More specifically the disclosure provides a procedure for privacy protection of user subscription and location related information at AS layer during AS connection establishment procedure.


