UE Session Security Attribute Matching for Signaling Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing end-to-end (E2E) security protection methods in data transmission fail to efficiently manage session establishment and user plane protocol stack selection for different services, leading to unnecessary signaling exchanges and potential security vulnerabilities.

Innovation Solution

A data transmission method where user equipment (UE) determines the security attributes of its sessions and sends session establishment requests to the control plane node only when these attributes do not meet the required security parameters of an application, thereby triggering the establishment of sessions tailored to specific security requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a new session is established for each service, then security requirements of different applications are met, but unnecessary signaling exchanges occur and network resources are wasted

Engineering Contradiction:
Improvesecurity requirement complianceVSAvoidsignaling exchange overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The network side pre-establishes multiple sessions with different security attributes before service requests arrive. When an application needs a session, the UE and network can quickly match and reuse an existing session that meets the security requirements, avoiding the need to establish a new session from scratch and reducing signaling overhead.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically selects and reuses sessions based on the specific security attributes required by different applications. The session selection is flexible and adaptive, matching the dynamic security needs of various services while efficiently utilizing pre-established session resources.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If multiple sessions with different security attributes are maintained, then diverse service security needs are met, but session selection complexity increases

Engineering Contradiction:
Improveservice security requirement coverageVSAvoidsession selection complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

Sessions are segmented and categorized according to their specific security attributes (such as encryption algorithms, key lengths, and security protocols). This segmentation allows the UE to efficiently search and select appropriate sessions by matching security attribute requirements, reducing the complexity of session selection while maintaining support for diverse service needs.

Inventive Principle:
Principle #1Segmentation

3Reliability

If session establishment is triggered for every service, then security is ensured, but network signaling overhead increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidnetwork signaling overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

Multiple sessions with different security attributes are pre-established and stored in the UE before service requests arrive. When an application needs a session, the system can quickly match and reuse an existing session that meets the security requirements, avoiding the need to establish a new session from scratch and reducing signaling overhead.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3873121B1Data transmission method, user equipment, and control plane node
Publication Date: 2025.05.07 HUAWEI TECH CO LTD
  • EP3873121B1 patent drawingFigure 1~2
  • EP3873121B1 patent drawingFigure 3A~3B
  • EP3873121B1 patent drawingFigure 3C

AI summary

Embodiments of the present invention relate to a data transmission method, user equipment, and a control plane node. User equipment UE determines a security attribute of a session of the UE; the UE sends a session establishment request message to a control plane node when the security attribute of the session of the UE does not meet a security requirement of an application, where the session establishment request message is used to request to establish a session corresponding to the security requirement of the application. To be specific, the UE determines, based on the security requirement of the application, whether the session of the UE corresponds to the security requirement of the application. When the security attribute of the UE does not meet the security requirement of the application, a session establishment process is triggered to establish a session corresponding to the security requirement, to reduce an unnecessary signaling exchange caused by establishment of a new session in a data transmission process, thereby meeting requirements of different services.