Secure UE Configuration Updates Through Native NAS Control Plane
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile networks require the deployment of a dedicated network element, such as an OTA Gateway, to update configuration parameters in User Equipment (UE), which is inefficient and lacks end-to-end security.
Innovation Solution
The solution involves using Non-Access Stratum (NAS) messages for secure updates of UE configuration parameters, where the Unified Data Management (UDM) assembles and secures the updates, which are then transmitted via the Access and Mobility Management Function (AMF) to the UE using a control plane message, ensuring end-to-end security and eliminating the need for a dedicated network element.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a dedicated network element (OTA Gateway) is deployed to update configuration parameters in UE, then the update functionality is provided, but the device complexity and network infrastructure requirements increase
Solution Approach 1:
The patent applies universality by enabling existing native control plane network elements (AMF, UDM) to perform configuration parameter update functions. Instead of requiring a dedicated OTA Gateway, the AMF and UDM are enhanced to handle configuration updates through existing control plane signaling mechanisms, allowing these elements to serve multiple functions including mobility management, authentication, and configuration provisioning.
Solution Approach 2:
The patent implements self-service by allowing the UE to receive configuration parameter updates directly through the control plane without requiring a separate dedicated service infrastructure. The native control plane elements automatically handle the update process using existing signaling pathways, eliminating the need for additional service-specific network elements.
2Reliability
If traditional update methods are used without end-to-end security, then the update process is simpler, but the security and integrity of configuration parameters are compromised
Solution Approach 1:
The patent applies preliminary anti-action by implementing security protection mechanisms in advance before the configuration parameter update is transmitted. The UDM applies integrity protection and ciphering to the configuration parameters before sending them to the AMF, and the AMF further protects the parameters before forwarding to the UE. This preemptive security approach prevents potential tampering or interception throughout the transmission path.
Solution Approach 2:
The patent uses intermediary elements (AMF and UDM) that provide security services between the configuration parameter source and the UE. These native control plane elements act as trusted intermediaries that apply security protections and verify integrity, ensuring secure end-to-end transmission without requiring a dedicated secure update infrastructure.
3Productivity
If native control plane functionalities are used for updates, then the productivity and efficiency improve, but the complexity of securing these existing functionalities increases
Solution Approach 1:
The patent merges the configuration parameter update function with existing native control plane functionalities. The AMF and UDM, which already handle mobility management and subscription data, are enhanced to also perform configuration updates. This consolidation allows updates to occur through existing efficient control plane signaling pathways without requiring separate dedicated update mechanisms, thereby maintaining high productivity.
Solution Approach 2:
The patent enables the AMF and UDM to serve multiple functions including their original roles plus configuration parameter management. By making these elements multi-functional, the system achieves efficient updates through existing control plane infrastructure while distributing the security implementation across established trusted network elements rather than adding new complexity.
Data Source
AI summary
Systems and methods that update configuration parameters on a UE using control plane functionalities. In one embodiment, an AMF element of a mobile network receives a control plane message from a UDM element that includes a UE configuration parameter update for the UE. The UE configuration parameter update is security protected via a secured packet, integrity protection, etc. The AMF element is configured to transparently send the UE configuration parameter update to the UE. Thus, AMF element inserts the UE configuration parameter update (that is security protected) in a container of a Non-Access Stratum (NAS) message, and sends the NAS message to the UE. The UE may then update its configuration parameters based on the update when security checks are complete.


