5G NSSAI Encryption via AS Security Context

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The 5G system's inability to securely send Network Slice Selection Assistance Information (NSSAI) in clear text raises security concerns, leading to potential network congestion and inefficient resource allocation, as the AMF may become overwhelmed and signaling overhead increases due to incorrect AMF selection and resource allocation issues.

Innovation Solution

A mobile communication system that encrypts NSSAI using an Access Stratum (AS) security context, allowing secure transmission and decryption by User Equipment (UE) and Radio Access Network (RAN) nodes, ensuring secure NSSAI exchange and preventing network congestion.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If NSSAI is transmitted in clear text in RRC layer, then transmission simplicity is improved, but user privacy and security are compromised

Engineering Contradiction:
Improvetransmission simplicityVSAvoiduser privacy security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary encryption mechanism using AS security context between UE and RAN. The NSSAI information is encrypted using AS security context before transmission in RRC messages, and decrypted by RAN using the same AS security context. This intermediary encryption layer protects user privacy while maintaining the efficiency of RRC layer transmission.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If NSSAI is encrypted using AS security context, then user privacy is protected, but transmission complexity increases

Engineering Contradiction:
Improveuser privacy securityVSAvoidencryption complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service encryption where both UE and RAN possess the AS security context and can independently perform encryption and decryption operations. The UE encrypts NSSAI using its AS security context before transmission, and RAN decrypts using its own AS security context upon reception. This self-service approach distributes the cryptographic burden and simplifies the overall system architecture.

Inventive Principle:
Principle #25Self-service

3Productivity

If correct AMF selection is enabled through NSSAI transmission, then network resource allocation efficiency is improved, but signaling overhead increases due to security procedures

Engineering Contradiction:
Improvenetwork resource allocation efficiencyVSAvoidsignaling overhead
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The patent applies preliminary action by establishing AS security context before NSSAI transmission occurs. The security context is set up in advance during initial connection establishment, enabling subsequent encrypted NSSAI transmissions without repeated security setup procedures. This preliminary security establishment reduces signaling overhead in later communications while ensuring correct AMF selection through secure NSSAI delivery.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240236661A9Procedure to update the parameters related to unified access control
Publication Date: 2024.07.11 NEC CORP
  • US20240236661A9 patent drawing
  • US20240236661A9 patent drawing
  • US20240236661A9 patent drawing

AI summary

This disclosure defines a procedure to security protection to sensitive information in AS layer during AS connection establishment procedure. More specifically the disclosure provides a procedure for privacy protection of user subscription and location related information at AS layer during AS connection establishment procedure.