Separate NAS Connection Counts for Parallel Access Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 5G Systems, the security mechanisms for multiple connections via 3GPP and non-3GPP accesses face challenges with unreliable in-order delivery of NAS messages, leading to issues of future proofness, concurrency, and agnosticism, particularly in scenarios where a UE is registered simultaneously over different access types.
Innovation Solution
Implementing a method that provides separate NAS connection identifications and NAS count domains for each connection, using a shared master key and unique NAS connection identifiers (NAS CONN ID) to ensure cryptographic separation and maintain in-order delivery of NAS messages across parallel connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If separate NAS connections are established for 3GPP and non-3GPP accesses, then security and flexibility for multiple connections are enhanced, but device complexity and management overhead increase
Solution Approach 1:
The patent segments the NAS count domain into separate portions for different NAS connections (3GPP and non-3GPP). Each connection receives a dedicated count portion, allowing independent management and tracking of message sequences per connection while maintaining overall system security through the shared master key.
2Adaptability or versatility
If NAS messages are transmitted over multiple parallel connections, then communication flexibility improves, but reliable in-order delivery becomes unreliable
Solution Approach 1:
The patent divides the NAS count domain into separate portions for each connection, enabling independent sequence numbering per connection. This segmentation allows the system to track and ensure in-order delivery within each connection independently, even when messages traverse multiple parallel connections simultaneously.
Solution Approach 2:
The patent performs preliminary allocation of distinct NAS count portions to each connection before message transmission begins. This pre-configuration ensures that each connection has its own dedicated counter space, enabling reliable sequencing and order tracking to be established in advance, preventing delivery issues before they occur.
3Productivity
If a shared master key is used for multiple NAS connections, then security efficiency improves, but cryptographic separation between connections is reduced
Solution Approach 1:
The patent segments the cryptographic namespace by allocating separate NAS count portions to each connection while maintaining the shared master key. This segmentation provides cryptographic separation through distinct count values and connection identifiers, ensuring that compromise of one connection's counters does not affect others, while still benefiting from the efficiency of key sharing.
Data Source
AI summary
A first communication node may provide first and second NAS connection identifications for respective first and second NAS connections between the first and a second communication node, with the first and second NAS connection identifications being different and the first and second NAS connections being different. A first NAS message may be communicated between the first and second communication nodes over the first NAS connection, including at performing integrity protection for the first NAS message using the first NAS connection identification and/or performing confidentiality protection for the first NAS message using the first NAS connection identification. A second NAS message may be communicated between the first and second communication nodes over the second NAS connection, including performing integrity protection for the second NAS message using the second NAS connection identification and/or performing confidentiality protection for the second NAS message for confidentiality protection using the second NAS connection identification.


