RAN Node On-Demand System Information Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G radio communication networks, RAN nodes cannot authenticate radio terminals during on-demand SI requests, leading to potential resource wastage by broadcasting SI to malicious terminals.

Innovation Solution

Implementing a procedure where radio terminals transmit a Non-Access Stratum (NAS) security parameter to RAN nodes, which then send an authentication request to the core network, and only broadcast on-demand SI if the terminal is successfully authenticated.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If RAN node broadcasts on-demand SI in response to any random access request, then ease of operation is improved, but loss of energy and resources increases due to potential malicious requests

Engineering Contradiction:
Improveease of SI requestVSAvoidenergy waste
Core Design Contradiction:
Ease of operationVSLoss of energy

Solution Approach 1:

The patent applies preliminary action by performing authentication of the radio terminal before broadcasting the on-demand system information. The RAN node authenticates the terminal using NAS security parameters exchanged during the random access procedure, and only broadcasts the SI if authentication succeeds. This prevents energy waste by avoiding broadcasts to malicious or unauthenticated terminals while maintaining ease of operation for legitimate users.

Inventive Principle:
Principle #10Preliminary action

2Loss of energy

If RAN node performs authentication before broadcasting on-demand SI, then loss of energy is reduced, but device complexity increases due to additional authentication procedure

Engineering Contradiction:
Improveenergy conservationVSAvoidprocedure complexity
Core Design Contradiction:
Loss of energyVSDevice complexity

Solution Approach 1:

The patent merges the authentication function with the existing random access procedure. The NAS security parameters are exchanged during the standard random access messages (Msg3 and Msg4), and the RAN node uses these existing parameters for authentication purposes. This integration avoids adding separate authentication steps, thereby reducing procedural complexity while still achieving energy conservation through selective SI broadcasting.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If RAN node uses NAS security parameter for authentication, then reliability is improved by preventing malicious requests, but difficulty of detecting and measuring increases due to security processing

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidsecurity parameter processing
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies self-service by having the radio terminal itself provide the NAS security parameters (such as 5G-S-TMSI and gNB identifier) during the random access procedure. These parameters are already computed and prepared by the terminal for normal communication operations. The RAN node simply uses these pre-available parameters for authentication, avoiding complex security processing and detection while achieving reliable authentication to prevent malicious requests.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12149932B2Radio terminal, RAN node, core network node, and methods therefor
Publication Date: 2024.11.19 NEC CORP
  • US12149932B2 patent drawing
  • US12149932B2 patent drawing
  • US12149932B2 patent drawing

AI summary

A RAN node (2) receives a message containing a Non-Access Stratum (NAS) security parameter from a radio terminal (1), during a procedure in which the radio terminal (1) requests the RAN node to broadcast on-demand system information. The RAN node (2) sends an authentication request message containing the NAS security parameter to a core network node (3), in order to request authentication of the radio terminal (1). The RAN node (2) broadcasts the on-demand system information in response to receiving from the core network node (3) an authentication response message indicating successful authentication of the radio terminal (1). This can contribute to, for example, preventing on-demand SI from being broadcast in response to a request from a malicious radio terminal.