RAN-Indicated AS Security for Signaling-Only Connections
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the 5G System (5GS) architecture, there is an inefficiency in establishing access stratum (AS) security for signaling-only connections, as the AMF may not be aware of the need for security information, leading to unnecessary resource consumption and inefficient use of UE contexts.
Innovation Solution
A method and system where the RAN indicates to the AMF the need for security information, allowing the AMF to trigger the appropriate UE context setup procedures only when necessary, thereby optimizing resource usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the AMF triggers NG Context Setup procedure for every UE signaling connection, then security information is reliably provided to RAN, but unnecessary resource consumption occurs and UE contexts are created when not needed
Solution Approach 1:
The RAN node performs preliminary determination of whether AS security is needed based on events it is aware of (such as redirection to another RAT or MDT reporting), and proactively indicates this need to the AMF before the AMF would otherwise trigger a full context setup. This allows the AMF to prepare security information in advance only when actually needed, avoiding unnecessary resource consumption while ensuring security information is available when required.
Solution Approach 2:
The RAN node provides feedback to the AMF about the need for security information by including an indication in the Initial UE Message. This feedback mechanism allows the AMF to adjust its behavior and only trigger NG Context Setup procedure when the RAN actually needs security information, thereby improving resource usage efficiency while maintaining reliable security information provision.
2Productivity
If the AMF does not trigger NG Context Setup procedure, then resource consumption is reduced, but security information may not be provided when needed
Solution Approach 1:
The RAN node monitors events and provides feedback to the AMF about the need for security information through the Initial UE Message. This ensures that the AMF only triggers NG Context Setup when actually needed, improving resource efficiency while maintaining reliable security information availability through the feedback mechanism.
Solution Approach 2:
The Initial UE Message acts as an intermediary carrier that conveys the RAN node's indication of security information needs to the AMF. This intermediary mechanism enables efficient coordination between RAN and AMF, allowing the AMF to trigger context setup only when necessary while ensuring security information is available when required.
3Reliability
If AS security is established for all connections, then security coverage is maximized, but unnecessary UE contexts are created and resources are wasted
Solution Approach 1:
The RAN node performs preliminary determination of whether AS security is needed based on events it is aware of, and proactively indicates this need to the AMF. This allows the system to establish AS security only when actually needed, maximizing security coverage for connections that require it while avoiding the creation of unnecessary UE contexts and reducing overall complexity.
Solution Approach 2:
The system applies AS security locally only to connections where it is actually needed, rather than universally applying it to all connections. The RAN node's event-based determination and indication mechanism enables this localized approach, ensuring security coverage is maximized for connections requiring it while avoiding unnecessary UE context creation and resource waste.
Data Source
AI summary
A method for securing radio connections comprises performing a connection setup with a user equipment (UE); determine that security information is needed for the UE based on an event which triggers a need of the security information; send an indication to a second network node to request the security information for the UE; and receiving the security information from the network node via a UE context setup procedure. The method may avoid a waste of resource in network by determining whether the UE is required to set up a security procedure by either a network node of a radio access network or a management and function node of a core network.


