5G User Plane Security Contexts for Inactive-State Resumption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The 5G mobile communications system introduces user plane integrity protection but does not address user plane security in the inactive scenario, leading to a gap in ensuring data security during state transitions.

Innovation Solution

A communication method and apparatus that determine a user plane security protection method and key upon receiving an RRC resume message, performing security deprotection and protection on uplink data to ensure secure data transmission in the inactive scenario.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If user plane security protection is not applied in inactive state, then communication interruption delay is reduced and state transition is faster, but user plane data transmission security is compromised

Engineering Contradiction:
Improvecommunication interruption delayVSAvoiduser plane data transmission security
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-establishing security contexts and configuration information before the UE enters inactive state. The source base station stores security protection methods and keys in the context information, which are then retrieved by the target base station during state transition, enabling rapid security activation without full re-establishment procedures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses context information as an intermediary carrier that transports security protection methods and keys between source and target base stations. This intermediary mechanism allows security parameters to be efficiently transferred and activated during state transitions without direct complex negotiations between all network elements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If user plane security protection is applied in inactive state, then data transmission security is ensured, but system complexity and processing overhead increase

Engineering Contradiction:
Improveuser plane data transmission securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the essential security protection methods and keys from the complete security establishment procedure and stores them separately in context information. This extraction allows the system to activate only the necessary security components during inactive state transitions, avoiding the complexity of full security re-establishment while maintaining adequate protection.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the parameter state of security protection by transitioning from a fully established security context in connected state to a condensed security configuration in inactive state. The security protection method and key parameters are preserved in a compact form in context information, enabling rapid activation with reduced processing overhead.

Inventive Principle:
Principle #35Parameter changes

3Quantity of substance

If security context is deleted in idle state, then memory resources are freed, but security re-establishment time increases when transitioning to connected state

Engineering Contradiction:
Improvememory resourcesVSAvoidsecurity re-establishment time
Core Design Contradiction:
Quantity of substanceVSLoss of time

Solution Approach 1:

The patent applies preliminary action by retaining essential security configuration information in context data before transitioning to idle state. When the UE needs to resume connection, the target base station can quickly retrieve these pre-stored security parameters from context information, avoiding time-consuming security re-establishment procedures while maintaining acceptable memory usage.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4593437A1Communication method and communications apparatus
Publication Date: 2025.07.30 HUAWEI TECH CO LTD
  • EP4593437A1 patent drawingFigure 1
  • EP4593437A1 patent drawingFigure 2
  • EP4593437A1 patent drawingFigure 3

AI summary

Embodiments of this application provide a communication method and a communications apparatus. The method includes: after receiving an RRC resume message from user equipment, determining, by a target access network device, a first user plane security protection method between the target access network device and the user equipment based on a context information obtaining response from a source access network device; determining a first user plane security key between the target access network device and the user equipment, when receiving first uplink user plane data from the user equipment, performing user plane security deprotection on the first uplink user plane data based on the first user plane security key and the first user plane security protection method, to obtain uplink user plane data; and sending the uplink user plane data. According to the embodiments of this application, user plane security in an inactive scenario can be ensured, thereby ensuring user plane data transmission security in the inactive scenario.