UE Security Capabilities in LTE to 5G Handover
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In wireless communications, the transition from LTE to 5G networks poses challenges in ensuring UE security capabilities, particularly during handovers, as legacy network elements may not support new radio (NR) security features, leading to potential bidding-down attacks and inadequate security protections.
Innovation Solution
A method and device for obtaining UE NR security capabilities involve indicating to the UE to send its NR security capabilities during specific network events like X2 or S1 handovers, ensuring these capabilities are included in messages like RRC connection reconfiguration or handover confirm messages, and utilizing existing mechanisms to protect against bidding-down attacks without requiring changes to legacy MMEs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If legacy network elements are used during handover, then network compatibility is maintained, but UE NR security capabilities cannot be obtained leading to security vulnerabilities
Solution Approach 1:
The target base station prepares an indication message in advance during the handover request acknowledge phase, instructing the UE to include NR security capabilities in the connection reconfiguration complete message. This preliminary action ensures that security capabilities are obtained before the handover is finalized, preventing security vulnerabilities while maintaining compatibility with legacy elements.
Solution Approach 2:
The patent introduces an indication message as an intermediary mechanism between the target base station and the UE. This indication serves as a mediator that triggers the UE to provide NR security capabilities without requiring changes to the legacy MME, thus bridging the gap between legacy network elements and new security requirements.
2Reliability
If UE NR security capabilities are requested during handover, then security protection is improved, but additional signaling messages are required increasing communication overhead
Solution Approach 1:
The patent merges the NR security capabilities transmission with the existing RRC connection reconfiguration complete message. Instead of creating a separate signaling exchange, the indication to provide security capabilities is embedded in the handover procedure, and the capabilities themselves are included in the already-necessary connection reconfiguration complete message, thus avoiding additional signaling overhead.
3Reliability
If changes are made to legacy MME to support NR security capabilities, then security capability management is improved, but network device complexity increases
Solution Approach 1:
The patent extracts the NR security capabilities obtaining function from the legacy MME and relocates it to the base station level. The target base station directly communicates with the UE to obtain NR security capabilities through the indication mechanism, eliminating the need for legacy MME modifications while maintaining centralized security capability management.
Data Source
AI summary
A method and apparatus are provided for delivering user equipment (UE) new radio (NR) security capabilities and mobility management entity interworking. In the embodiments, adding the UE NR security capabilities in a new information element over a non-access stratum (NAS) is compatible with a legacy mobility management entity and eliminate any potential of bidding-down attack and is more advantageous and serves the security solution better. As long as the UE is connected to the long term evolution (LTE) and all UE security capabilities including LTE security capabilities have been replayed correctly and successfully in the NAS security mode command (SMC) message, the UE may not consider the absence of the UE NR security capabilities in the NAS SMC as a security vulnerability.


