RAN-Indicated AS Security for Signaling-Only Connections

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the 5G System (5GS) architecture, there is an inefficiency in establishing access stratum (AS) security for signaling-only connections, as the AMF may not be aware of the need for security information, leading to unnecessary resource consumption and inefficient use of UE contexts.

Innovation Solution

A method and system where the RAN indicates to the AMF the need for security information, allowing the AMF to trigger the appropriate UE context setup procedures only when necessary, thereby optimizing resource usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the AMF triggers NG Context Setup procedure for every UE signaling connection, then security information is reliably provided to RAN, but unnecessary resource consumption occurs and UE contexts are created when not needed

Engineering Contradiction:
Improvesecurity information provisionVSAvoidresource usage efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The RAN node performs preliminary determination of whether AS security is needed based on events it is aware of (such as redirection to another RAT or MDT reporting), and proactively indicates this need to the AMF before the AMF would otherwise trigger a full context setup. This allows the AMF to prepare security information in advance only when actually needed, avoiding unnecessary resource consumption while ensuring security information is available when required.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The RAN node provides feedback to the AMF about the need for security information by including an indication in the Initial UE Message. This feedback mechanism allows the AMF to adjust its behavior and only trigger NG Context Setup procedure when the RAN actually needs security information, thereby improving resource usage efficiency while maintaining reliable security information provision.

Inventive Principle:
Principle #23Feedback

2Productivity

If the AMF does not trigger NG Context Setup procedure, then resource consumption is reduced, but security information may not be provided when needed

Engineering Contradiction:
Improveresource usage efficiencyVSAvoidsecurity information availability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The RAN node monitors events and provides feedback to the AMF about the need for security information through the Initial UE Message. This ensures that the AMF only triggers NG Context Setup when actually needed, improving resource efficiency while maintaining reliable security information availability through the feedback mechanism.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The Initial UE Message acts as an intermediary carrier that conveys the RAN node's indication of security information needs to the AMF. This intermediary mechanism enables efficient coordination between RAN and AMF, allowing the AMF to trigger context setup only when necessary while ensuring security information is available when required.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If AS security is established for all connections, then security coverage is maximized, but unnecessary UE contexts are created and resources are wasted

Engineering Contradiction:
Improvesecurity coverageVSAvoidUE context management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The RAN node performs preliminary determination of whether AS security is needed based on events it is aware of, and proactively indicates this need to the AMF. This allows the system to establish AS security only when actually needed, maximizing security coverage for connections that require it while avoiding the creation of unnecessary UE contexts and reducing overall complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies AS security locally only to connections where it is actually needed, rather than universally applying it to all connections. The RAN node's event-based determination and indication mechanism enables this localized approach, ensuring security coverage is maximized for connections requiring it while avoiding unnecessary UE context creation and resource waste.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12452768B2Method, apparatus, and system for securing radio connections
Publication Date: 2025.10.21 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US12452768B2 patent drawing
  • US12452768B2 patent drawing
  • US12452768B2 patent drawing

AI summary

A method for securing radio connections comprises performing a connection setup with a user equipment (UE); determine that security information is needed for the UE based on an event which triggers a need of the security information; send an indication to a second network node to request the security information for the UE; and receiving the security information from the network node via a UE context setup procedure. The method may avoid a waste of resource in network by determining whether the UE is required to set up a security procedure by either a network node of a radio access network or a management and function node of a core network.