NSSAI Encryption During 5G Registration for Secure Slice Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless communications systems face security threats due to unprotected exchange of sensitive network slice selection assistance information (NSSAI) before access stratum security setup, making UEs susceptible to identification and service exploitation.

Innovation Solution

The proposed solution involves encrypting NSSAI using a shared security key between the UE, AMF, and base station, ensuring secure communication by encrypting and decrypting NSSAI values during the connection procedure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If NSSAI is exchanged in clear text during connection procedure, then signaling overhead is reduced and communication is simpler, but security is compromised making UE susceptible to identification and service exploitation

Engineering Contradiction:
ImprovesecurityVSAvoidencryption complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by performing encryption of NSSAI values before they are transmitted during the connection procedure. The UE encrypts the NSSAI using a security key derived from the gNB ID and other parameters, so that the encrypted values are already prepared when needed for transmission, eliminating the need for real-time encryption during the critical connection setup phase.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism by using a derived security key that incorporates the gNB ID. This key acts as a mediator that allows the UE to encrypt NSSAI values specifically for transmission to a particular gNB, enabling secure communication without requiring complex pre-shared keys between all network entities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption is applied to NSSAI during connection procedure, then security is enhanced, but processing time and latency increase

Engineering Contradiction:
ImprovesecurityVSAvoidconnection setup latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The security key is derived in advance using a deterministic function of the gNB ID and other available parameters. This preliminary key derivation allows the UE to immediately encrypt NSSAI values when the connection procedure requires them, without needing to wait for complex key exchange protocols to complete.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The UE performs self-service by autonomously deriving the security key and encrypting its own NSSAI values using locally available information (gNB ID from system information). This eliminates the need for the network to provide encryption keys or for complex mutual authentication protocols, significantly reducing the time required for secure NSSAI transmission.

Inventive Principle:
Principle #25Self-service

3Reliability

If encrypted NSSAI values are transmitted, then security risks are decreased, but device complexity increases due to encryption and decryption operations

Engineering Contradiction:
ImprovesecurityVSAvoidoperational simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent changes the parameter used for encryption from complex pre-shared keys to a derived key based on the gNB ID and other readily available parameters. This transformation simplifies the encryption operation to a deterministic function that can be performed with minimal computational resources, making the system easier to operate while maintaining security.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3874781B1Encrypting network slice selection assistance information
Publication Date: 2025.08.06 QUALCOMM INC
  • EP3874781B1 patent drawingFigure 1
  • EP3874781B1 patent drawingFigure 2
  • EP3874781B1 patent drawingFigure 3

AI summary

Methods, systems, and devices for wireless communications are described. A user equipment (UE) may participate in a registration procedure with an access and mobility management function (AMF). The UE may transmit to the AMF, as part of the registration procedure, an indication of one or more single network slice selection assistance information (S-NSSAI) or a network slice selection assistance information (NSSAI). Following, the UE may receive a control message from the AMF, wherein the control message includes one or more encrypted S-NSSAI values or an encrypted NSSAI value based on the indication. The UE may then transmit the encrypted S-NSSAI or the encrypted NSSAI to a base station as part of a message.