Satellite Store-and-Forward Security via Home Network Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security mechanisms for 5G mobile networks are inefficient or inoperable for store and forward services, particularly in satellite access scenarios where end-to-end connectivity is intermittent, leading to security vulnerabilities.

Innovation Solution

Enhanced security mechanisms are implemented, providing integrity protection and encryption through Message Authentication Codes (MAC) derived from home network keys, Non-Access Stratum (NAS) integrity keys, and newly-defined NTN tokens, ensuring secure packet transmission even without end-to-end connectivity between User Equipment (UE) and the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If store and forward service is implemented for satellite access, then service availability is improved for mobile users, but security protection becomes insufficient due to intermittent connectivity

Engineering Contradiction:
Improveservice availabilityVSAvoidsecurity protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by performing integrity protection and encryption on packets at the home network and serving network before the packets are transmitted via satellite. Security keys and integrity protection mechanisms are pre-established, allowing secure store and forward operations even when end-to-end connectivity is intermittent. This ensures security is in place before the actual transmission occurs.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If traditional end-to-end security mechanisms are used, then security integrity is maintained, but service continuity is broken during satellite connectivity interruptions

Engineering Contradiction:
Improvesecurity integrityVSAvoidservice continuity
Core Design Contradiction:
ReliabilityVSDuration of action of moving object

Solution Approach 1:

The patent segments the security protection into multiple independent stages: home network security processing, serving network security processing, and satellite transmission. Each segment can operate independently, allowing the packet to be secured at home network, stored, then forwarded through satellite without requiring continuous end-to-end connectivity. This segmentation enables service continuity while maintaining security integrity.

Inventive Principle:
Principle #1Segmentation

3Reliability

If security processing is performed at multiple network points, then security coverage is enhanced, but system complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements universal security processing functions at both the home network and serving network that perform similar integrity protection and encryption operations. This multi-functionality approach uses standardized security mechanisms that can operate at different network points, enhancing security coverage while avoiding the need for completely different security systems at each location, thus controlling complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP4432579A1Security for store and forward service via satellite access
Publication Date: 2024.09.18 NOKIA TECHNOLOGIES OY
  • EP4432579A1 patent drawingFigure 1~2
  • EP4432579A1 patent drawingFigure 3
  • EP4432579A1 patent drawingFigure 4

AI summary

Systems, methods, and software of performing a store and forward service for mobile terminated messages to user equipment via satellite access. In an embodiment, a home network of user equipment (UE) receives a first message request from an application server that includes a secured packet destined for the user equipment via satellite access, and determines whether the user equipment supports the store and forward service via satellite access. When the user equipment supports the store and forward service, the home network provides integrity protection of the secured packet at the home network by deriving a message authentication code based on the secured packet and a home network key, and send a second message request to a serving network of the user equipment with the secured packet and the message authentication code contained in a home network container.