PDU Session Security Reuse for Dual Connectivity Consistency
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The 5G wireless communication systems face challenges in establishing protocol data unit (PDU) sessions with inconsistent and potentially compromised security settings due to differing capabilities between Master and Secondary Nodes in Dual Connectivity scenarios, particularly in scenarios requiring redundant data transmission for Ultra-Reliable and Low Latency Communication (URLLC) services.
Innovation Solution
A method where the Session Management Function (SMF) in the core network generates and stores user plane (UP) security enforcement information for PDU sessions, ensuring consistent security settings are applied across both the Master Node (MN) and Secondary Node (SN) by storing and reusing the same UP security enforcement information for subsequent PDU sessions, and allowing the Master Node to modify and store security settings before forwarding them to the Secondary Node.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If UP security enforcement information is generated and stored by the SMF for subsequent PDU sessions, then security consistency across multiple PDU sessions is improved, but the complexity of the core network node increases
Solution Approach 1:
The SMF generates and stores UP security enforcement information in advance before PDU sessions are established. This preliminary action ensures that when PDU sessions are set up, the security information is already available, eliminating the need for complex real-time security decision-making and reducing operational complexity while maintaining security consistency.
Solution Approach 2:
The SMF creates a copy of the UP security enforcement information and stores it for reuse in subsequent PDU sessions. This copying mechanism allows the same security settings to be applied consistently across multiple sessions without requiring the SMF to regenerate security information each time, thereby simplifying the core network node operations while ensuring security reliability.
2Adaptability or versatility
If the Master Node modifies UP security enforcement information before forwarding to the Secondary Node, then adaptability to different node capabilities is improved, but the risk of security settings compromise increases
Solution Approach 1:
The Master Node applies local modifications to the UP security enforcement information based on its own capabilities and the Secondary Node's capabilities before forwarding. This local quality approach allows each node to customize security settings according to its specific capabilities while maintaining overall security consistency, reducing the risk of compromise by ensuring settings are appropriate for each node's capabilities.
Solution Approach 2:
The Master Node receives feedback about the Secondary Node's capabilities and uses this information to adjust the UP security enforcement information before forwarding. This feedback mechanism ensures that security settings are adapted to match the actual capabilities of each node, preventing security compromises while maintaining adaptability across different node configurations.
3Reliability
If redundant PDU sessions are established for URLLC services, then data transmission reliability is improved, but the complexity of managing security settings increases
Solution Approach 1:
The SMF uses a universal approach by generating and storing UP security enforcement information that can be applied to multiple PDU sessions. This multi-functional security information template allows the same security settings to be reused across redundant PDU sessions established for URLLC services, maintaining data transmission reliability while significantly reducing the complexity of managing security settings for each individual session.
Data Source
Figure 1A~1B
Figure 2
Figure 3
AI summary
A method performed by a core network node in a core network of a wireless communication system includes receiving (1102) a first request to establish a first protocol data unit, PDU, session between a user equipment, UE and a user plane function in the core network, generating (1104) user plane, UP, security enforcement information, to be applied to the first PDU session, transmitting (1106) the UP security enforcement information to a radio access network, RAN, node for establishing the first PDU session, and storing (1108) the UP security enforcement information for use in establishing a subsequent PDU session for the UE.