Secure UE Configuration Updates Through Native NAS Control Plane

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile networks require the deployment of a dedicated network element, such as an OTA Gateway, to update configuration parameters in User Equipment (UE), which is inefficient and lacks end-to-end security.

Innovation Solution

The solution involves using Non-Access Stratum (NAS) messages for secure updates of UE configuration parameters, where the Unified Data Management (UDM) assembles and secures the updates, which are then transmitted via the Access and Mobility Management Function (AMF) to the UE using a control plane message, ensuring end-to-end security and eliminating the need for a dedicated network element.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a dedicated network element (OTA Gateway) is deployed to update configuration parameters in UE, then the update functionality is provided, but the device complexity and network infrastructure requirements increase

Engineering Contradiction:
Improveconfiguration parameter update capabilityVSAvoidnetwork element deployment
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies universality by enabling existing native control plane network elements (AMF, UDM) to perform configuration parameter update functions. Instead of requiring a dedicated OTA Gateway, the AMF and UDM are enhanced to handle configuration updates through existing control plane signaling mechanisms, allowing these elements to serve multiple functions including mobility management, authentication, and configuration provisioning.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements self-service by allowing the UE to receive configuration parameter updates directly through the control plane without requiring a separate dedicated service infrastructure. The native control plane elements automatically handle the update process using existing signaling pathways, eliminating the need for additional service-specific network elements.

Inventive Principle:
Principle #25Self-service

2Reliability

If traditional update methods are used without end-to-end security, then the update process is simpler, but the security and integrity of configuration parameters are compromised

Engineering Contradiction:
Improveend-to-end securityVSAvoidsecurity protection mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary anti-action by implementing security protection mechanisms in advance before the configuration parameter update is transmitted. The UDM applies integrity protection and ciphering to the configuration parameters before sending them to the AMF, and the AMF further protects the parameters before forwarding to the UE. This preemptive security approach prevents potential tampering or interception throughout the transmission path.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent uses intermediary elements (AMF and UDM) that provide security services between the configuration parameter source and the UE. These native control plane elements act as trusted intermediaries that apply security protections and verify integrity, ensuring secure end-to-end transmission without requiring a dedicated secure update infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If native control plane functionalities are used for updates, then the productivity and efficiency improve, but the complexity of securing these existing functionalities increases

Engineering Contradiction:
Improveupdate efficiencyVSAvoidsecurity implementation in control plane
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent merges the configuration parameter update function with existing native control plane functionalities. The AMF and UDM, which already handle mobility management and subscription data, are enhanced to also perform configuration updates. This consolidation allows updates to occur through existing efficient control plane signaling pathways without requiring separate dedicated update mechanisms, thereby maintaining high productivity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent enables the AMF and UDM to serve multiple functions including their original roles plus configuration parameter management. By making these elements multi-functional, the system achieves efficient updates through existing control plane infrastructure while distributing the security implementation across established trusted network elements rather than adding new complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12432550B2Systems and method for secure updates of configuration parameters provisioned in user equipment
Publication Date: 2025.09.30 NOKIA TECHNOLOGIES OY
  • US12432550B2 patent drawing
  • US12432550B2 patent drawing
  • US12432550B2 patent drawing

AI summary

Systems and methods that update configuration parameters on a UE using control plane functionalities. In one embodiment, an AMF element of a mobile network receives a control plane message from a UDM element that includes a UE configuration parameter update for the UE. The UE configuration parameter update is security protected via a secured packet, integrity protection, etc. The AMF element is configured to transparently send the UE configuration parameter update to the UE. Thus, AMF element inserts the UE configuration parameter update (that is security protected) in a container of a Non-Access Stratum (NAS) message, and sends the NAS message to the UE. The UE may then update its configuration parameters based on the update when security checks are complete.