UE Session Security Attribute Matching for Signaling Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing end-to-end (E2E) security protection methods in data transmission fail to efficiently manage session establishment and user plane protocol stack selection for different services, leading to unnecessary signaling exchanges and potential security vulnerabilities.
Innovation Solution
A data transmission method where user equipment (UE) determines the security attributes of its sessions and sends session establishment requests to the control plane node only when these attributes do not meet the required security parameters of an application, thereby triggering the establishment of sessions tailored to specific security requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a new session is established for each service, then security requirements of different applications are met, but unnecessary signaling exchanges occur and network resources are wasted
Solution Approach 1:
The network side pre-establishes multiple sessions with different security attributes before service requests arrive. When an application needs a session, the UE and network can quickly match and reuse an existing session that meets the security requirements, avoiding the need to establish a new session from scratch and reducing signaling overhead.
Solution Approach 2:
The system dynamically selects and reuses sessions based on the specific security attributes required by different applications. The session selection is flexible and adaptive, matching the dynamic security needs of various services while efficiently utilizing pre-established session resources.
2Adaptability or versatility
If multiple sessions with different security attributes are maintained, then diverse service security needs are met, but session selection complexity increases
Solution Approach 1:
Sessions are segmented and categorized according to their specific security attributes (such as encryption algorithms, key lengths, and security protocols). This segmentation allows the UE to efficiently search and select appropriate sessions by matching security attribute requirements, reducing the complexity of session selection while maintaining support for diverse service needs.
3Reliability
If session establishment is triggered for every service, then security is ensured, but network signaling overhead increases
Solution Approach 1:
Multiple sessions with different security attributes are pre-established and stored in the UE before service requests arrive. When an application needs a session, the system can quickly match and reuse an existing session that meets the security requirements, avoiding the need to establish a new session from scratch and reducing signaling overhead.
Data Source
Figure 1~2
Figure 3A~3B
Figure 3C
AI summary
Embodiments of the present invention relate to a data transmission method, user equipment, and a control plane node. User equipment UE determines a security attribute of a session of the UE; the UE sends a session establishment request message to a control plane node when the security attribute of the session of the UE does not meet a security requirement of an application, where the session establishment request message is used to request to establish a session corresponding to the security requirement of the application. To be specific, the UE determines, based on the security requirement of the application, whether the session of the UE corresponds to the security requirement of the application. When the security attribute of the UE does not meet the security requirement of the application, a session establishment process is triggered to establish a session corresponding to the security requirement, to reduce an unnecessary signaling exchange caused by establishment of a new session in a data transmission process, thereby meeting requirements of different services.