Session Management Authorization Token for 5G PDU Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In next-generation wireless communication networks like 5G, the separation of mobility management and session management functions from the Mobility Management Entity (MME) poses challenges in ensuring secure and authorized session establishment for User Equipment (UE) across different network locations, particularly due to the potential for unauthorized modifications by Access and Mobility Function (AMF) entities.

Innovation Solution

The implementation of a method that involves generating and transmitting an authorization token based on session parameters and a key received from a Security Anchor Function (SEAF) or a third-party AAA server, ensuring that only authorized User Equipment (UE) can establish a Protocol Data Unit (PDU) session within a logical data network, thereby securing session management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If mobility management and session management functions are separated from the MME in next-generation networks, then network functionality and flexibility are improved, but security risks and vulnerability to unauthorized modifications increase

Engineering Contradiction:
Improvenetwork functionalityVSAvoidsession security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an authorization token as an intermediary mechanism between the AMF and SMF. The token, generated by the SEAF based on security parameters and session information, mediates the authorization process to ensure that session management operations are performed only by authorized entities, thus resolving the security risk introduced by functional separation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If session management is performed by a logically separate SMF from the AMF, then system modularity and flexibility are improved, but the risk of unauthorized modifications by AMF entities increases

Engineering Contradiction:
Improvesystem modularityVSAvoidunauthorized modifications
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by generating the authorization token in advance, before the SMF performs session management operations. The token pre-encodes the authorized operations and parameters, preventing any unauthorized modifications by the AMF during the session establishment process, thus counteracting the security risk before it can manifest.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The authorization token serves as an intermediary that carries security credentials from the SEAF to the SMF. This intermediary mechanism ensures that even though the SMF is logically separate from the AMF, the SMF can verify authorization independently through the token, preventing unauthorized modifications while maintaining system modularity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If an authorization token is generated and transmitted to verify UE authorization, then session security and integrity are improved, but signaling overhead and processing complexity increase

Engineering Contradiction:
Improvesession integrityVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security verification functionality into a separate authorization token generation process performed by the SEAF. This extraction allows the SMF to focus on session management while delegating security token generation to a dedicated security function, thereby improving session integrity without significantly increasing the processing complexity of the session management entity itself.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10841084B2Session management authorization token
Publication Date: 2020.11.17 QUALCOMM INC
  • US10841084B2 patent drawing
  • US10841084B2 patent drawing
  • US10841084B2 patent drawing

AI summary

Techniques are described that provide a session management authorization token by receiving a session request message to establish a protocol data unit (PDU) session for a logical data network associated with a user equipment (UE), the session request message may include one or more session parameters; verifying that the UE is authorized to establish the PDU session for the logical data network; receiving a key associated with the PDU session; generating an authorization token based on the received key and the session parameters; and transmitting a session response message including the generated authorization token to the UE.