Separate NAS Connection Counts for Parallel Access Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G Systems, the security mechanisms for multiple connections via 3GPP and non-3GPP accesses face challenges with unreliable in-order delivery of NAS messages, leading to issues of future proofness, concurrency, and agnosticism, particularly in scenarios where a UE is registered simultaneously over different access types.

Innovation Solution

Implementing a method that provides separate NAS connection identifications and NAS count domains for each connection, using a shared master key and unique NAS connection identifiers (NAS CONN ID) to ensure cryptographic separation and maintain in-order delivery of NAS messages across parallel connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If separate NAS connections are established for 3GPP and non-3GPP accesses, then security and flexibility for multiple connections are enhanced, but device complexity and management overhead increase

Engineering Contradiction:
Improvesupport for multiple NAS connectionsVSAvoidconnection management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the NAS count domain into separate portions for different NAS connections (3GPP and non-3GPP). Each connection receives a dedicated count portion, allowing independent management and tracking of message sequences per connection while maintaining overall system security through the shared master key.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If NAS messages are transmitted over multiple parallel connections, then communication flexibility improves, but reliable in-order delivery becomes unreliable

Engineering Contradiction:
Improveparallel connection capabilityVSAvoidin-order message delivery
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent divides the NAS count domain into separate portions for each connection, enabling independent sequence numbering per connection. This segmentation allows the system to track and ensure in-order delivery within each connection independently, even when messages traverse multiple parallel connections simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary allocation of distinct NAS count portions to each connection before message transmission begins. This pre-configuration ensures that each connection has its own dedicated counter space, enabling reliable sequencing and order tracking to be established in advance, preventing delivery issues before they occur.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If a shared master key is used for multiple NAS connections, then security efficiency improves, but cryptographic separation between connections is reduced

Engineering Contradiction:
Improvesecurity processing efficiencyVSAvoidsecurity isolation between connections
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the cryptographic namespace by allocating separate NAS count portions to each connection while maintaining the shared master key. This segmentation provides cryptographic separation through distinct count values and connection identifiers, ensuring that compromise of one connection's counters does not affect others, while still benefiting from the efficiency of key sharing.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250294351A1Methods providing security for multiple NAS connections using separate counts and related network nodes and wireless terminals
Publication Date: 2025.09.18 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20250294351A1 patent drawing
  • US20250294351A1 patent drawing
  • US20250294351A1 patent drawing

AI summary

A first communication node may provide first and second NAS connection identifications for respective first and second NAS connections between the first and a second communication node, with the first and second NAS connection identifications being different and the first and second NAS connections being different. A first NAS message may be communicated between the first and second communication nodes over the first NAS connection, including at performing integrity protection for the first NAS message using the first NAS connection identification and/or performing confidentiality protection for the first NAS message using the first NAS connection identification. A second NAS message may be communicated between the first and second communication nodes over the second NAS connection, including performing integrity protection for the second NAS message using the second NAS connection identification and/or performing confidentiality protection for the second NAS message for confidentiality protection using the second NAS connection identification.