5G UE Security Information Synchronization Method

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G communication systems, the separation of mobility management and session management entities introduces security challenges due to outdated security information, making user equipment (UE) and networks vulnerable to attacks, as they lack synchronized security protocols.

Innovation Solution

A method and apparatus for managing and synchronizing security information between UE and network entities through a security scheme that includes transmitting registration requests with security information, authentication requests, and security mode commands to ensure up-to-date security key processing capabilities and validity, preventing security weaknesses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security information is not synchronized between UE and network entities, then system complexity is reduced, but security reliability deteriorates making systems vulnerable to attacks

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsecurity synchronization complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by performing security information synchronization during the initial registration phase and authentication phase, before actual data transmission begins. The UE and network entities exchange and align security capabilities, security keys, and security parameters in advance through registration request/messages and authentication request/response sequences, ensuring security is established before communication starts.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the UE and network entities continuously exchange security status information. The network entity receives security capability information from the UE during registration, and both parties exchange authentication information during the authentication phase. This feedback loop ensures that security information remains synchronized and allows detection of any desynchronization that may occur during operation.

Inventive Principle:
Principle #23Feedback

2Reliability

If security information is continuously synchronized between UE and network entities, then security reliability is improved, but communication time increases due to additional signaling

Engineering Contradiction:
Improvesecurity synchronizationVSAvoidcommunication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs security synchronization in advance during the registration and authentication phases, which occur only once or occasionally during the communication session. By completing security information exchange, capability matching, and key establishment beforehand, the system avoids the need for frequent synchronization during data transmission, thus minimizing time loss while maintaining security reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements periodic security synchronization at specific phases (registration, authentication, and optionally security mode command) rather than continuously during all communication activities. This periodic approach ensures security is maintained at critical intervals without the overhead of continuous synchronization, balancing security reliability with communication efficiency.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS12200481B2Method and apparatus for protecting information in wireless communication system
Publication Date: 2025.01.14 SAMSUNG ELECTRONICS CO LTD
  • US12200481B2 patent drawing
  • US12200481B2 patent drawing
  • US12200481B2 patent drawing

AI summary

The disclosure relates to a method and apparatus for protecting information in a wireless communication system, and an operating method of a user equipment (UE) in the wireless communication system may include: transmitting, to an access and mobility management function (AMF), a registration request message including security information related to a security key processing capability of the UE; receiving, from the AMF, an authentication request message; transmitting, to the AMF, an authentication response message in response to the authentication request message; receiving, from the AMF, a security mode command message; and transmitting a security mode complete message in response to the security mode command message.