NSSAI Encryption During 5G Registration for Secure Slice Selection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wireless communications systems face security threats due to unprotected exchange of sensitive network slice selection assistance information (NSSAI) before access stratum security setup, making UEs susceptible to identification and service exploitation.
Innovation Solution
The proposed solution involves encrypting NSSAI using a shared security key between the UE, AMF, and base station, ensuring secure communication by encrypting and decrypting NSSAI values during the connection procedure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If NSSAI is exchanged in clear text during connection procedure, then signaling overhead is reduced and communication is simpler, but security is compromised making UE susceptible to identification and service exploitation
Solution Approach 1:
The patent applies preliminary action by performing encryption of NSSAI values before they are transmitted during the connection procedure. The UE encrypts the NSSAI using a security key derived from the gNB ID and other parameters, so that the encrypted values are already prepared when needed for transmission, eliminating the need for real-time encryption during the critical connection setup phase.
Solution Approach 2:
The patent introduces an intermediary mechanism by using a derived security key that incorporates the gNB ID. This key acts as a mediator that allows the UE to encrypt NSSAI values specifically for transmission to a particular gNB, enabling secure communication without requiring complex pre-shared keys between all network entities.
2Reliability
If encryption is applied to NSSAI during connection procedure, then security is enhanced, but processing time and latency increase
Solution Approach 1:
The security key is derived in advance using a deterministic function of the gNB ID and other available parameters. This preliminary key derivation allows the UE to immediately encrypt NSSAI values when the connection procedure requires them, without needing to wait for complex key exchange protocols to complete.
Solution Approach 2:
The UE performs self-service by autonomously deriving the security key and encrypting its own NSSAI values using locally available information (gNB ID from system information). This eliminates the need for the network to provide encryption keys or for complex mutual authentication protocols, significantly reducing the time required for secure NSSAI transmission.
3Reliability
If encrypted NSSAI values are transmitted, then security risks are decreased, but device complexity increases due to encryption and decryption operations
Solution Approach 1:
The patent changes the parameter used for encryption from complex pre-shared keys to a derived key based on the gNB ID and other readily available parameters. This transformation simplifies the encryption operation to a deterministic function that can be performed with minimal computational resources, making the system easier to operate while maintaining security.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Methods, systems, and devices for wireless communications are described. A user equipment (UE) may participate in a registration procedure with an access and mobility management function (AMF). The UE may transmit to the AMF, as part of the registration procedure, an indication of one or more single network slice selection assistance information (S-NSSAI) or a network slice selection assistance information (NSSAI). Following, the UE may receive a control message from the AMF, wherein the control message includes one or more encrypted S-NSSAI values or an encrypted NSSAI value based on the indication. The UE may then transmit the encrypted S-NSSAI or the encrypted NSSAI to a base station as part of a message.