User Plane Gateway Security Context for PDU Session Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile communication security is compromised during data transmission as data is decrypted and integrity verified by access network devices, exposing it to tampering risks, especially during user plane gateway switching.

Innovation Solution

A method and apparatus for obtaining a security context to enable end-to-end security protection by establishing a new security context during user plane gateway switching, involving the user equipment, session management network elements, and access and mobility management network elements to ensure secure data transmission between the user equipment and the new user plane gateway.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is decrypted and integrity verified by access network devices during transmission, then data privacy and integrity can be ensured at the access level, but security risks arise during transmission through the secure path after decryption

Engineering Contradiction:
Improvedata integrityVSAvoiddata tampering risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the security protection into two distinct layers: user plane security protection between UE and user plane gateway, and control plane security protection between UE and access network device. This segmentation allows each layer to independently provide security without compromising the other, resolving the contradiction between ensuring data integrity at access level and preventing tampering risks during transmission.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a user plane gateway as an intermediary that establishes end-to-end encrypted tunnels between UE and the gateway. This intermediary enables secure direct communication while allowing the access network device to perform its decryption and integrity verification functions without exposing data to tampering risks during transmission through the secure path.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If user plane gateway switching is performed due to network load or service requirements, then network flexibility and service continuity are improved, but security protection is compromised during the switching process

Engineering Contradiction:
Improvegateway switching capabilityVSAvoidsecurity protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent establishes user plane security protection and security contexts before gateway switching occurs. By pre-configuring security parameters and encrypted tunnels, the system ensures that security protection is already in place when switching happens, preventing security compromises during the transition process while maintaining gateway switching flexibility.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamic security context management that adapts to gateway switching. Security contexts are established, maintained, and transferred dynamically during the switching process, allowing the system to maintain security protection while adapting to changing network conditions and gateway assignments.

Inventive Principle:
Principle #15Dynamics

3Reliability

If a new security context is established during PDU session reestablishment, then end-to-end security protection is improved, but system complexity increases due to additional security context management

Engineering Contradiction:
Improveend-to-end security protectionVSAvoidsecurity context management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal security context management mechanism that handles multiple functions: establishing security contexts for new PDU sessions, maintaining security contexts during gateway switching, and transferring security contexts during session reestablishment. This multi-functional approach reduces overall system complexity by consolidating security management tasks into a unified framework.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11722888B2Security context obtaining method and apparatus
Publication Date: 2023.08.08 HUAWEI TECH CO LTD
  • US11722888B2 patent drawing
  • US11722888B2 patent drawing
  • US11722888B2 patent drawing

AI summary

This application provides a security context obtaining method and apparatus. The method includes: receiving, by a user plane gateway, a PDU session establishment request from UE, where the PDU session establishment request is used to request to establish a PDU session between the user plane gateway and the UE, and the PDU session is carried between the UE and a service server of a data network; and separately obtaining, by the user plane gateway and the UE, a security context used for the PDU session, and activating user plane security protection based on the security context. Therefore, during PDU session reestablishment, for example, PDU session reestablishment triggered by switching of the user plane gateway, a session management network element, and the like, the user plane gateway and the UE can obtain a new security context, thereby achieving end-to-end protection between the UE and the user plane gateway.