Terminal PDU Session Migration Security Check

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the transition from 5G to EPS, user equipment (UE) faces challenges in migrating PDU sessions due to differences in user plane security capabilities, leading to potential unsatisfactory security requirements and increased signaling overheads.

Innovation Solution

The UE determines the user plane security status of a PDU session by parsing packets and comparing it with the security capabilities of the EPS, ensuring that only sessions matching the EPS's security standards are migrated, thereby avoiding unsatisfactory security requirements and reducing unnecessary signaling.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the UE migrates all PDU sessions to the EPS without checking security capabilities, then the migration process is simple and fast, but the user plane security requirements cannot be satisfied

Engineering Contradiction:
Improveuser plane security capabilityVSAvoidsession migration process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The UE performs preliminary detection of user plane security enforcement information (encryption and integrity protection status) before initiating PDU session migration to the EPS. This advance checking ensures that only sessions compatible with EPS security capabilities are migrated, preventing security violations while maintaining a relatively simple migration process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The UE autonomously detects and determines the user plane security status of PDU sessions by examining security enforcement information in downlink packets. The terminal independently assesses whether sessions meet EPS security requirements and makes migration decisions without requiring complex network-side coordination, thereby ensuring security compliance while keeping the process efficient.

Inventive Principle:
Principle #25Self-service

2Reliability

If the UE checks user plane security enforcement information for each PDU session, then the security requirements are satisfied, but the signaling overhead increases

Engineering Contradiction:
Improveuser plane security capabilityVSAvoidsignaling overhead
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The UE extracts and examines only the critical user plane security enforcement information (encryption status and integrity protection status) from downlink packets to determine migration eligibility. By focusing on these specific security parameters rather than进行全面 checking, the UE ensures security requirements are met while minimizing the processing overhead and avoiding unnecessary signaling.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If the UE migrates PDU sessions with integrity protection requirements to the EPS, then all sessions are migrated, but the security capability mismatch causes migration failure

Engineering Contradiction:
Improvesession migration efficiencyVSAvoidsecurity capability compatibility
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The UE checks the integrity protection requirement status as part of the preliminary security capability assessment before migration. By detecting whether PDU sessions require integrity protection in advance, the UE identifies sessions that would be incompatible with EPS capabilities and excludes them from migration, ensuring both high migration efficiency for compatible sessions and security capability compatibility.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3833075B1Efficient session migration due to support by a terminal
Publication Date: 2024.07.03 HUAWEI TECH CO LTD
  • EP3833075B1 patent drawingFigure 1A
  • EP3833075B1 patent drawingFigure 1B
  • EP3833075B1 patent drawingFigure 1C-1

AI summary

This application provides a session migration method and apparatus. When a terminal apparatus moves from a 5GS to an EPS, the terminal apparatus needs to establish a corresponding PDN connection in the EPS for a PDU session in the 5GS. Before establishing the PDN connection, the terminal apparatus needs to determine that a user plane security status of the PDU session matches user plane encryption protection information of the EPS. This avoids that a PDU session that does not satisfy a user plane security requirement is migrated to the EPS, and reduces unnecessary signaling overheads.