Satellite Store-and-Forward Security via Home Network Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security mechanisms for 5G mobile networks are inefficient or inoperable for store and forward services, particularly in satellite access scenarios where end-to-end connectivity is intermittent, leading to security vulnerabilities.
Innovation Solution
Enhanced security mechanisms are implemented, providing integrity protection and encryption through Message Authentication Codes (MAC) derived from home network keys, Non-Access Stratum (NAS) integrity keys, and newly-defined NTN tokens, ensuring secure packet transmission even without end-to-end connectivity between User Equipment (UE) and the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If store and forward service is implemented for satellite access, then service availability is improved for mobile users, but security protection becomes insufficient due to intermittent connectivity
Solution Approach 1:
The patent applies preliminary action by performing integrity protection and encryption on packets at the home network and serving network before the packets are transmitted via satellite. Security keys and integrity protection mechanisms are pre-established, allowing secure store and forward operations even when end-to-end connectivity is intermittent. This ensures security is in place before the actual transmission occurs.
2Reliability
If traditional end-to-end security mechanisms are used, then security integrity is maintained, but service continuity is broken during satellite connectivity interruptions
Solution Approach 1:
The patent segments the security protection into multiple independent stages: home network security processing, serving network security processing, and satellite transmission. Each segment can operate independently, allowing the packet to be secured at home network, stored, then forwarded through satellite without requiring continuous end-to-end connectivity. This segmentation enables service continuity while maintaining security integrity.
3Reliability
If security processing is performed at multiple network points, then security coverage is enhanced, but system complexity increases
Solution Approach 1:
The patent implements universal security processing functions at both the home network and serving network that perform similar integrity protection and encryption operations. This multi-functionality approach uses standardized security mechanisms that can operate at different network points, enhancing security coverage while avoiding the need for completely different security systems at each location, thus controlling complexity.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
Systems, methods, and software of performing a store and forward service for mobile terminated messages to user equipment via satellite access. In an embodiment, a home network of user equipment (UE) receives a first message request from an application server that includes a secured packet destined for the user equipment via satellite access, and determines whether the user equipment supports the store and forward service via satellite access. When the user equipment supports the store and forward service, the home network provides integrity protection of the secured packet at the home network by deriving a message authentication code based on the secured packet and a home network key, and send a second message request to a serving network of the user equipment with the secured packet and the message authentication code contained in a home network container.