Security Token Mechanism for Lower Layer Mobility Commands

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G NR specifications lack security mechanisms for mobility procedures controlled by lower layer signaling, such as MAC CE, making them vulnerable to unauthorized access and hijacking during inter-cell mobility and multi-TRP communications.

Innovation Solution

Introducing a security token mechanism where the UE obtains and stores security tokens, which are included in lower layer mobility commands to ensure authorization, preventing unauthorized access by comparing the received token with the stored token, and updating tokens after each authorized command.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security mechanisms are added to lower layer mobility commands, then security against unauthorized access and hijacking is improved, but device complexity and signaling overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the state of the mobility command by adding a security token parameter. This token serves as an authentication credential that verifies the command's origin, transforming an insecure command structure into a secure one without fundamentally altering the mobility procedure's operation

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The security token acts as an intermediary element between the network node and UE. It mediates the authorization verification process by providing a tangible credential that the UE can check against stored tokens, eliminating the need for complex real-time authentication protocols

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security tokens are verified in every mobility command, then protection against replay attacks is improved, but processing time and signaling overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The UE performs preliminary action by storing security tokens in advance before receiving mobility commands. This pre-stored credential system enables immediate verification without real-time computation, reducing processing time during actual mobility operations

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security token serves as a copy of authorization credentials that can be verified locally by the UE without requiring continuous communication with the network node. This copying mechanism eliminates repeated authentication handshakes, reducing signaling overhead and processing time

Inventive Principle:
Principle #26Copying

Data Source

PatentEP4073996B1User equipment, network node and methods in a wireless communications network
Publication Date: 2024.03.20 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP4073996B1 patent drawingFigure 1
  • EP4073996B1 patent drawingFigure 2
  • EP4073996B1 patent drawingFigure 3

AI summary

A method performed by a User Equipment, UE, for handling authorization in relation to a mobility procedure in a wireless communications network is provided. The UE obtains (901) at least one security token. The UE receives (903) a mobility command for the mobility procedure from a network node in the wireless communications network. The mobility command comprises a security token. The mobility command relates to a protocol layer below a Radio Resource Control, RRC, protocol. The UE then decides (904) whether or not the mobility command is authorized, based on comparing the security token in the mobility command with the at least one obtained security token.