SNPN Credential Transmission Security via DRB Indication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies face challenges in securely transmitting stand-alone non-public network (SNPN) credentials to terminals, particularly in ensuring security protection during user plane connections, which can lead to authentication failures or unauthorized access to malicious networks.

Innovation Solution

A credential transmission method and apparatus that involves receiving first indication information from a base station to determine whether to activate or deactivate user plane security protection for a data radio bearer (DRB) used for transmitting SNPN credentials, allowing the terminal to independently verify and respond to the security protection activation requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If user plane security protection is activated for DRB transmitting SNPN credentials, then security and reliability of credential transmission is improved, but device complexity and operational complexity increase

Engineering Contradiction:
Improvesecurity and reliability of credential transmissionVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The terminal autonomously determines whether to activate user plane security protection for the DRB based on received indication information, and independently performs the security protection activation. This self-service approach reduces network-side operational complexity while ensuring security requirements are met.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The network sends indication information in advance to guide the terminal on whether security protection should be activated. The terminal then performs the security protection activation before credential transmission occurs, ensuring security is established proactively rather than reactively.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the terminal independently verifies and responds to security protection activation requests, then security control and reliability are improved, but processing time and operational complexity increase

Engineering Contradiction:
Improvesecurity controlVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The terminal performs verification and response only for the specific DRB carrying SNPN credentials, rather than applying security protection universally to all data bearers. This partial action approach maintains security control where needed while minimizing unnecessary processing time and complexity.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250088849A1Credential transmission method and apparatus, communication device, and storage medium
Publication Date: 2025.03.13 BEIJING XIAOMI MOBILE SOFTWARE CO LTD
  • US20250088849A1 patent drawing
  • US20250088849A1 patent drawing
  • US20250088849A1 patent drawing

AI summary

A credential transmission method includes receiving, by a terminal, first indication information sent by a base station. The first indication information is used for indicating that a user plane security protection operation of a data radio bearer (DRB) of the terminal is requested to be activated or not to be activated. The DRB is at least used for bearing a credential required by the terminal for accessing a stand-alone non-public network (SNPN).