Secure Non-3GPP Access Using 3GPP Credentials and Direct UPF Links
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing 3GPP access technologies face challenges in establishing secure non-3GPP connections directly with user plane functions in wireless networks without intermediaries, such as Non-3GPP Inter-Working Functions (N3IWF), and there is a need for efficient and secure connectivity solutions.
Innovation Solution
A method and system for configuring a secure non-3GPP connection using existing 3GPP access credentials, where a wireless transmit and/or receive unit (WTRU) generates new security credentials to establish a direct connection with a user plane function (UPF) in the wireless network, and the UPF also participates in this process by receiving and using these credentials to set up the secure connection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If a direct secure non-3GPP connection is established between WTRU and UPF without N3IWF, then connection efficiency and speed are improved, but security reliability deteriorates
Solution Approach 1:
The patent introduces N3IWF as an intermediary security gateway that enables secure non-3GPP access. The N3IWF establishes a secure connection between the WTRU and the 5G core network, providing authentication and security services while allowing direct user plane connectivity to UPF. This resolves the contradiction by maintaining security through the intermediary while achieving connection efficiency through direct user plane path.
2Ease of operation
If existing 3GPP credentials are reused for non-3GPP access, then ease of operation is improved, but device complexity increases
Solution Approach 1:
The patent implements universality by enabling WTRUs to use their existing 3GPP credentials (KgNB) for both 3GPP and non-3GPP access scenarios. The N3IWF and UPF are configured to accept and validate these existing credentials, allowing the same credential set to serve multiple access types. This eliminates the need for separate credential management while maintaining security, thus improving ease of operation without significantly increasing device complexity.
3Device complexity
If N3IWF is removed from the architecture, then device complexity is reduced, but security protection deteriorates
Solution Approach 1:
The N3IWF serves as a critical intermediary that provides security functions including authentication, key derivation, and secure tunnel establishment for non-3GPP access. It protects the user plane connection by establishing a secure context between WTRU and UPF. Removing N3IWF would eliminate these security functions, creating vulnerability. The patent maintains N3IWF in the architecture to preserve security while optimizing the user plane path.
4Productivity
If direct UPF connection is established, then productivity is improved, but reliability of secure connection deteriorates
Solution Approach 1:
The patent segments the connection into two independent parts: a control plane path through N3IWF for security management, and a user plane path directly to UPF for data transmission. This segmentation allows the user plane to achieve high productivity through direct connectivity while the control plane maintains security reliability through the authenticated N3IWF path. The separation of control and user planes enables both efficiency and security to coexist.
Data Source
AI summary
A process for establishing a secure non-3GPP connection between a wireless transmit and/or receive unit (WTRU) and a wireless network using existing 3GPP access credentials. The WTRU transmits a request to establish a protocol data unit (PDU) session along with secure non-3GPP information to the wireless network. Upon receiving an acceptance indication, the WTRU generates new security credentials based on the existing 3GPP credentials and establishes the secure non-3GPP connection. Provisions are made for indicating 3GPP security capability of the secure non-3GPP connection, standalone non-3GPP connections, and secure connection termination at the user plane function (UPF). Additionally, new shared keys are generated for secure non-3GPP connectivity and handling handovers with updated 3GPP access credentials. The process ensures secure communication between the WTRU and the wireless network by leveraging security frameworks.


