User Plane Gateway Security Context for PDU Session Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile communication security is compromised during data transmission as data is decrypted and integrity verified by access network devices, exposing it to tampering risks, especially during user plane gateway switching.
Innovation Solution
A method and apparatus for obtaining a security context to enable end-to-end security protection by establishing a new security context during user plane gateway switching, involving the user equipment, session management network elements, and access and mobility management network elements to ensure secure data transmission between the user equipment and the new user plane gateway.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is decrypted and integrity verified by access network devices during transmission, then data privacy and integrity can be ensured at the access level, but security risks arise during transmission through the secure path after decryption
Solution Approach 1:
The patent segments the security protection into two distinct layers: user plane security protection between UE and user plane gateway, and control plane security protection between UE and access network device. This segmentation allows each layer to independently provide security without compromising the other, resolving the contradiction between ensuring data integrity at access level and preventing tampering risks during transmission.
Solution Approach 2:
The patent introduces a user plane gateway as an intermediary that establishes end-to-end encrypted tunnels between UE and the gateway. This intermediary enables secure direct communication while allowing the access network device to perform its decryption and integrity verification functions without exposing data to tampering risks during transmission through the secure path.
2Adaptability or versatility
If user plane gateway switching is performed due to network load or service requirements, then network flexibility and service continuity are improved, but security protection is compromised during the switching process
Solution Approach 1:
The patent establishes user plane security protection and security contexts before gateway switching occurs. By pre-configuring security parameters and encrypted tunnels, the system ensures that security protection is already in place when switching happens, preventing security compromises during the transition process while maintaining gateway switching flexibility.
Solution Approach 2:
The patent implements dynamic security context management that adapts to gateway switching. Security contexts are established, maintained, and transferred dynamically during the switching process, allowing the system to maintain security protection while adapting to changing network conditions and gateway assignments.
3Reliability
If a new security context is established during PDU session reestablishment, then end-to-end security protection is improved, but system complexity increases due to additional security context management
Solution Approach 1:
The patent creates a universal security context management mechanism that handles multiple functions: establishing security contexts for new PDU sessions, maintaining security contexts during gateway switching, and transferring security contexts during session reestablishment. This multi-functional approach reduces overall system complexity by consolidating security management tasks into a unified framework.
Data Source
AI summary
This application provides a security context obtaining method and apparatus. The method includes: receiving, by a user plane gateway, a PDU session establishment request from UE, where the PDU session establishment request is used to request to establish a PDU session between the user plane gateway and the UE, and the PDU session is carried between the UE and a service server of a data network; and separately obtaining, by the user plane gateway and the UE, a security context used for the PDU session, and activating user plane security protection based on the security context. Therefore, during PDU session reestablishment, for example, PDU session reestablishment triggered by switching of the user plane gateway, a session management network element, and the like, the user plane gateway and the UE can obtain a new security context, thereby achieving end-to-end protection between the UE and the user plane gateway.


