Terminal Radio Capability Data Security via NAS Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In communication networks, especially in scenarios where no security context is established between a terminal and a base station, private data transmitted by the terminal is vulnerable to theft or tampering, leading to security risks.

Innovation Solution

A data transmission method where the terminal performs NAS security protection on private data using a prestored NAS security context before establishing an AS security context, and sends the NAS-security-protected private data to the mobility management network element, which then forwards it to the access network device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If the terminal transmits private data without establishing an AS security context, then the transmission process can be simplified and faster, but the private data becomes vulnerable to theft or tampering

Engineering Contradiction:
Improvedata transmission speedVSAvoiddata security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent introduces the mobility management network element as an intermediary that receives and processes NAS-security-protected private data from the terminal before forwarding it to the access network device. This mediator enables secure data transmission without requiring the terminal to establish an AS security context with the access network device, thus maintaining transmission speed while ensuring data security through NAS-level protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the terminal performs AS security protection on private data, then the data security is ensured, but the terminal cannot do so without an established AS security context

Engineering Contradiction:
Improvedata securityVSAvoidsecurity context establishment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by having the terminal perform NAS security protection on private data before transmitting it to the mobility management network element, without waiting for AS security context establishment. The mobility management network element then performs security deprotection on the received data, enabling secure data handling in advance of AS security context establishment and avoiding the complexity of establishing AS security context solely for data protection.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If the mobility management network element performs security deprotection on NAS-security-protected private data, then the access network device can receive the decrypted private data, but additional processing steps are required

Engineering Contradiction:
Improvedata accessibilityVSAvoidprocessing steps
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the security deprotection function from the access network device and places it in the mobility management network element. The mobility management network element receives NAS-security-protected private data, performs security deprotection to obtain the original private data, and then forwards it to the access network device. This extraction simplifies the access network device's operations while centralizing security processing in the mobility management network element.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12317361B2Data transmission method and apparatus
Publication Date: 2025.05.27 HUAWEI TECH CO LTD
  • US12317361B2 patent drawing
  • US12317361B2 patent drawing
  • US12317361B2 patent drawing

AI summary

Embodiments of this application relate to the field of communication technologies, and provide a data transmission method and an apparatus, to ensure security of radio capability information of a terminal in a transmission process. The method includes: A terminal performs NAS security protection on radio capability information based on a NAS security context before establishing an AS security context; then the terminal sends the NAS-security-protected radio capability information to a mobility management network element; and after receiving the NAS-security-protected radio capability information, the mobility management network element performs security deprotection on the NAS-security-protected radio capability information, to obtain and store the radio capability information of the terminal. In this way, in a scenario in which an access network device requires the radio capability information of the terminal, the mobility management network element may send the radio capability information to the access network device.