Terminal Radio Capability Data Security via NAS Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In communication networks, especially in scenarios where no security context is established between a terminal and a base station, private data transmitted by the terminal is vulnerable to theft or tampering, leading to security risks.
Innovation Solution
A data transmission method where the terminal performs NAS security protection on private data using a prestored NAS security context before establishing an AS security context, and sends the NAS-security-protected private data to the mobility management network element, which then forwards it to the access network device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If the terminal transmits private data without establishing an AS security context, then the transmission process can be simplified and faster, but the private data becomes vulnerable to theft or tampering
Solution Approach 1:
The patent introduces the mobility management network element as an intermediary that receives and processes NAS-security-protected private data from the terminal before forwarding it to the access network device. This mediator enables secure data transmission without requiring the terminal to establish an AS security context with the access network device, thus maintaining transmission speed while ensuring data security through NAS-level protection.
2Reliability
If the terminal performs AS security protection on private data, then the data security is ensured, but the terminal cannot do so without an established AS security context
Solution Approach 1:
The patent applies preliminary action by having the terminal perform NAS security protection on private data before transmitting it to the mobility management network element, without waiting for AS security context establishment. The mobility management network element then performs security deprotection on the received data, enabling secure data handling in advance of AS security context establishment and avoiding the complexity of establishing AS security context solely for data protection.
3Ease of operation
If the mobility management network element performs security deprotection on NAS-security-protected private data, then the access network device can receive the decrypted private data, but additional processing steps are required
Solution Approach 1:
The patent extracts the security deprotection function from the access network device and places it in the mobility management network element. The mobility management network element receives NAS-security-protected private data, performs security deprotection to obtain the original private data, and then forwards it to the access network device. This extraction simplifies the access network device's operations while centralizing security processing in the mobility management network element.
Data Source
AI summary
Embodiments of this application relate to the field of communication technologies, and provide a data transmission method and an apparatus, to ensure security of radio capability information of a terminal in a transmission process. The method includes: A terminal performs NAS security protection on radio capability information based on a NAS security context before establishing an AS security context; then the terminal sends the NAS-security-protected radio capability information to a mobility management network element; and after receiving the NAS-security-protected radio capability information, the mobility management network element performs security deprotection on the NAS-security-protected radio capability information, to obtain and store the radio capability information of the terminal. In this way, in a scenario in which an access network device requires the radio capability information of the terminal, the mobility management network element may send the radio capability information to the access network device.


