UE Multi-NAS Security Contexts for Zero-Trust Roaming

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional telecommunications networks lack a secure and efficient mechanism for user equipment to establish direct, trusted connections with multiple network functions or services, leading to potential security vulnerabilities and limitations in roaming scenarios due to reliance on a single non-access stratum security context and a trusted core network domain.

Innovation Solution

Establishing multiple non-access stratum communication links and security contexts between user equipment and different network functions or services, allowing for a zero-trust architecture where each context is independently secured and managed, enabling direct, authenticated communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single non-access stratum security context is used for communication between user equipment and core network, then the system architecture is simpler, but security is compromised and roaming scenarios are limited

Engineering Contradiction:
ImprovesecurityVSAvoidsecurity context management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the single security context into multiple independent non-access stratum security contexts, each associated with a specific network function or service. This allows the user equipment to establish separate security contexts for different network functions (e.g., AMF, SMF, PCF), enabling independent security management for each context while maintaining overall system security. The segmentation resolves the contradiction by improving security through isolation without requiring complete redesign of the entire security architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension to security context management by enabling multiple parallel security contexts instead of a single hierarchical context. This dimensional change allows the system to maintain multiple independent security associations simultaneously, each with its own security parameters and trust relationships, thereby improving security and roaming capabilities without proportionally increasing overall system complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If multiple non-access stratum communication links are established with different network functions, then security and flexibility are enhanced, but system complexity increases

Engineering Contradiction:
Improvecommunication flexibilityVSAvoidcommunication link management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal non-access stratum communication framework that can be used across multiple network functions and services. The same communication mechanism and security context management approach is applied universally to different network functions (AMF, SMF, PCF, etc.), allowing the system to maintain multiple communication links with consistent management principles. This universality enhances flexibility and adaptability while controlling complexity through standardized procedures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent manages multiple communication links by dynamically changing security context parameters such as security identifiers, encryption keys, and authentication credentials for each link. Each non-access stratum communication link maintains its own set of security parameters that can be independently configured and managed. This parameter-based management approach enables flexible communication with multiple network functions while keeping the complexity of managing multiple links tractable through systematic parameter control.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If a trusted core network domain is assumed, then the system architecture is simpler, but security vulnerabilities arise in roaming scenarios

Engineering Contradiction:
ImprovesecurityVSAvoidtrust domain management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by establishing security contexts that are specific to each network function and each trust domain rather than assuming a universal trusted domain. Each non-access stratum security context is configured with appropriate trust relationships for its specific network function and domain, allowing the system to operate securely across multiple trust domains including roaming networks. This localized security approach improves reliability in roaming scenarios while managing complexity through domain-specific security configurations.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20260006434A1User equipment communicating with at least two of a plurality of network functions or services of a telecommunications network
Publication Date: 2026.01.01 DEUTSCHE TELEKOM AG
  • US20260006434A1 patent drawing
  • US20260006434A1 patent drawing
  • US20260006434A1 patent drawing

AI summary

The invention relates to a method for operating a user equipment with a telecommunications network and for communicating with at least two of a plurality of network functions or services of the telecommunications network or of a further telecommunications network, the plurality of network functions or services being able to provide different kinds of network function functionalities, wherein the user equipment is operated using at least a first non-access stratum communication link and a second non-access stratum communication link, the first non-access stratum communication link being established between the user equipment and a first network function or service of the plurality of network functions or services, and the second non-access stratum communication link being established between the user equipment and a second network function or service, wherein the first non-access stratum communication link involves establishing a first non-access stratum security context between the user equipment and the first network function or service and the second non-access stratum communication link involves establishing a second non-access stratum security context between the user equipment and the second network function or service, wherein the operation of the user equipment, using at least the first and second non-access stratum communication links, comprises the following steps: —in a first step, the first non-access stratum communication link as well as the first non-access stratum security context is established using a first non-access stratum endpoint information, and the second non-access stratum communication link as well as the second non-access stratum security context is established using a second non-access stratum endpoint information, —in a second step, the first and second non-access stratum communication links are used between their respective endpoints, wherein a first information element of or transmitted using the first non-access stratum security context is able to be referenced by a second information element of or transmitted using the second considered non-access stratum security context and/or wherein a first information element of or transmitted using the first non-access stratum security context is able to reference a second information element of or transmitted using the second considered non-access stratum security context.