Secure Non-3GPP Access Using 3GPP Credentials and Direct UPF Links

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing 3GPP access technologies face challenges in establishing secure non-3GPP connections directly with user plane functions in wireless networks without intermediaries, such as Non-3GPP Inter-Working Functions (N3IWF), and there is a need for efficient and secure connectivity solutions.

Innovation Solution

A method and system for configuring a secure non-3GPP connection using existing 3GPP access credentials, where a wireless transmit and/or receive unit (WTRU) generates new security credentials to establish a direct connection with a user plane function (UPF) in the wireless network, and the UPF also participates in this process by receiving and using these credentials to set up the secure connection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If a direct secure non-3GPP connection is established between WTRU and UPF without N3IWF, then connection efficiency and speed are improved, but security reliability deteriorates

Engineering Contradiction:
Improveconnection establishment speedVSAvoidsecurity reliability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent introduces N3IWF as an intermediary security gateway that enables secure non-3GPP access. The N3IWF establishes a secure connection between the WTRU and the 5G core network, providing authentication and security services while allowing direct user plane connectivity to UPF. This resolves the contradiction by maintaining security through the intermediary while achieving connection efficiency through direct user plane path.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If existing 3GPP credentials are reused for non-3GPP access, then ease of operation is improved, but device complexity increases

Engineering Contradiction:
Improvecredential management easeVSAvoidconnection configuration complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements universality by enabling WTRUs to use their existing 3GPP credentials (KgNB) for both 3GPP and non-3GPP access scenarios. The N3IWF and UPF are configured to accept and validate these existing credentials, allowing the same credential set to serve multiple access types. This eliminates the need for separate credential management while maintaining security, thus improving ease of operation without significantly increasing device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Device complexity

If N3IWF is removed from the architecture, then device complexity is reduced, but security protection deteriorates

Engineering Contradiction:
Improvenetwork architecture complexityVSAvoidsecurity vulnerability
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The N3IWF serves as a critical intermediary that provides security functions including authentication, key derivation, and secure tunnel establishment for non-3GPP access. It protects the user plane connection by establishing a secure context between WTRU and UPF. Removing N3IWF would eliminate these security functions, creating vulnerability. The patent maintains N3IWF in the architecture to preserve security while optimizing the user plane path.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If direct UPF connection is established, then productivity is improved, but reliability of secure connection deteriorates

Engineering Contradiction:
Improvedata transmission efficiencyVSAvoidsecure connection reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the connection into two independent parts: a control plane path through N3IWF for security management, and a user plane path directly to UPF for data transmission. This segmentation allows the user plane to achieve high productivity through direct connectivity while the control plane maintains security reliability through the authenticated N3IWF path. The separation of control and user planes enables both efficiency and security to coexist.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20260046621A1Methods, architectures, apparatuses, and systems for secure non-3GPP access
Publication Date: 2026.02.12 INTERDIGITAL PATENT HOLDINGS INC
  • US20260046621A1 patent drawing
  • US20260046621A1 patent drawing
  • US20260046621A1 patent drawing

AI summary

A process for establishing a secure non-3GPP connection between a wireless transmit and/or receive unit (WTRU) and a wireless network using existing 3GPP access credentials. The WTRU transmits a request to establish a protocol data unit (PDU) session along with secure non-3GPP information to the wireless network. Upon receiving an acceptance indication, the WTRU generates new security credentials based on the existing 3GPP credentials and establishes the secure non-3GPP connection. Provisions are made for indicating 3GPP security capability of the secure non-3GPP connection, standalone non-3GPP connections, and secure connection termination at the user plane function (UPF). Additionally, new shared keys are generated for secure non-3GPP connectivity and handling handovers with updated 3GPP access credentials. The process ensures secure communication between the WTRU and the wireless network by leveraging security frameworks.