NTN Access Stratum Security for Feeder Link Registration Gaps
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The intermittently unavailable feeder link in satellite communication networks due to satellite mobility disrupts conventional registration procedures, leading to timeouts and failure in establishing secure data transmission for user equipment (UE) with non-terrestrial networks (NTN), particularly for small data packets.
Innovation Solution
A provisional one-round-trip registration procedure is implemented, using a provisional NAS key derived without a full NAS security mode command, enabling protected small data transmission via a satellite feeder link, and employing null encryption and integrity protection algorithms for AS security during satellite transitions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional registration procedures are used in satellite communication networks, then full network registration and security establishment can be achieved, but the intermittently unavailable feeder link due to satellite mobility causes timeouts and registration failure
Solution Approach 1:
The patent implements a provisional registration procedure that performs only the essential authentication and security context establishment steps without completing the full multi-round-trip registration procedure. This partial action approach allows UEs to establish secure data transmission capability with minimal network interaction, avoiding timeouts caused by satellite mobility and feeder link unavailability.
2Reliability
If full network registration procedure is performed, then complete security context is established, but network resources are consumed and system efficiency decreases for small data packets
Solution Approach 1:
The patent extracts the essential security establishment functions from the complete registration procedure. By taking out only the critical authentication and security context setup steps while omitting unnecessary registration steps, the system achieves secure data transmission with reduced network resource consumption and improved efficiency for small data packets.
3Reliability
If conventional AS security configuration is used, then proper security algorithms are applied, but the multi-round-trip procedure fails due to satellite mobility and feeder link unavailability
Solution Approach 1:
The patent performs preliminary security configuration by establishing the AS security context and selecting security algorithms during the initial authentication phase before the feeder link becomes unavailable. This preliminary action ensures that security is properly configured in advance, avoiding the need for subsequent multi-round-trip procedures that would fail due to satellite mobility.
Data Source
AI summary
Various aspects of the present disclosure relate to transmitting a registration request message and receiving a registration accept message in plaintext, where the registration accept message comprises an authentication token and an access stratum (AS) security command from a satellite. Aspects of the present disclosure relate to transmitting, to the satellite, an AS security mode complete message in response to the AS security command and determining an authentication result based at least in part on the authentication token. Aspects of the present disclosure relate to transmitting, to a network function, a protected non-access stratum (NAS) request message using an AS security context based at least in part on the AS security command, where the protected NAS request message comprises the authentication result and a data packet.


