RRC-Inactive UE Verification for Secure Small Data Transmission

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing 5G communication systems face inefficiencies in managing user equipment (UE) security during inactive states, leading to increased power consumption, signaling overhead, and packet latency due to frequent transitions between RRC_INACTIVE and RRC_CONNECTED states for small data transmissions.

Innovation Solution

Implementing methods for generating and managing security keys and authentication tokens to enable secure small data transmissions (SDT) without anchor relocation, allowing UE to remain in the RRC_INACTIVE state, by utilizing pre-configured security keys and authentication tokens for communication with target gNBs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If user equipment frequently transitions between RRC_INACTIVE and RRC_CONNECTED states for small data transmissions, then data transmission capability is maintained, but power consumption increases and packet latency increases

Engineering Contradiction:
Improvedata transmission capabilityVSAvoidpower consumption
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The network pre-configures security keys and authentication tokens for target gNBs before the UE needs to transmit data. When UE is in RRC_INACTIVE state and needs to transmit small data, it can directly use the pre-configured security credentials to communicate with target gNBs without transitioning to RRC_CONNECTED state, thereby avoiding the power consumption associated with state transitions while maintaining data transmission capability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The UE is equipped with self-contained security credentials (security keys and authentication tokens) that allow it to independently authenticate with target gNBs without needing to establish a full RRC connection. This self-service mechanism enables the UE to perform small data transmissions autonomously in RRC_INACTIVE state, eliminating the need for network-assisted authentication that would require state transitions

Inventive Principle:
Principle #25Self-service

2Productivity

If user equipment frequently transitions between RRC_INACTIVE and RRC_CONNECTED states for small data transmissions, then data transmission capability is maintained, but signaling overhead increases

Engineering Contradiction:
Improvedata transmission capabilityVSAvoidsignaling overhead
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The network performs preliminary configuration of security keys and authentication tokens for multiple target gNBs in advance. This pre-configuration eliminates the need for repeated signaling exchanges during small data transmissions, as the UE can directly use the pre-configured credentials to communicate with target gNBs without initiating RRC connection establishment procedures

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention extracts the authentication and security management functions from the RRC connection establishment process. By separating these functions and providing them as pre-configured credentials to the UE, the system eliminates the signaling overhead associated with full RRC connection establishment while maintaining the ability to transmit data

Inventive Principle:
Principle #2Taking out (Extraction)

3Loss of energy

If pre-configured security keys are used for small data transmissions in RRC_INACTIVE state, then power consumption is reduced and signaling overhead is minimized, but network security verification complexity increases

Engineering Contradiction:
Improvepower consumptionVSAvoidsecurity verification complexity
Core Design Contradiction:
Loss of energyVSDevice complexity

Solution Approach 1:

The security verification process is segmented into two independent parts: authentication token verification (performed by target gNB using pre-shared security keys) and session management (handled separately). This segmentation allows the target gNB to verify authentication tokens efficiently without requiring complex multi-step authentication procedures, thus reducing the perceived complexity while maintaining security

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12432806B2Inactive user equipment verification for data transmission in communication network
Publication Date: 2025.09.30 NOKIA TECHNOLOGIES OY
  • US12432806B2 patent drawing
  • US12432806B2 patent drawing
  • US12432806B2 patent drawing

AI summary

Techniques are disclosed for verification of user equipment (UE) for small data transmission (SDT) when the user equipment is in an inactive state with respect to a communication network. For example, the UE is verified at a selected target gNB upon an SDT resume request initiated by the UE, i.e., a returning UE with respect to the selected target gNB, or otherwise prior to UE data resuming transmission to an anchor gNB from the selected target gNB.