5G User Plane Security Contexts for Inactive-State Resumption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The 5G mobile communications system introduces user plane integrity protection but does not address user plane security in the inactive scenario, leading to a gap in ensuring data security during state transitions.
Innovation Solution
A communication method and apparatus that determine a user plane security protection method and key upon receiving an RRC resume message, performing security deprotection and protection on uplink data to ensure secure data transmission in the inactive scenario.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of time
If user plane security protection is not applied in inactive state, then communication interruption delay is reduced and state transition is faster, but user plane data transmission security is compromised
Solution Approach 1:
The patent applies preliminary action by pre-establishing security contexts and configuration information before the UE enters inactive state. The source base station stores security protection methods and keys in the context information, which are then retrieved by the target base station during state transition, enabling rapid security activation without full re-establishment procedures.
Solution Approach 2:
The patent uses context information as an intermediary carrier that transports security protection methods and keys between source and target base stations. This intermediary mechanism allows security parameters to be efficiently transferred and activated during state transitions without direct complex negotiations between all network elements.
2Reliability
If user plane security protection is applied in inactive state, then data transmission security is ensured, but system complexity and processing overhead increase
Solution Approach 1:
The patent extracts the essential security protection methods and keys from the complete security establishment procedure and stores them separately in context information. This extraction allows the system to activate only the necessary security components during inactive state transitions, avoiding the complexity of full security re-establishment while maintaining adequate protection.
Solution Approach 2:
The patent changes the parameter state of security protection by transitioning from a fully established security context in connected state to a condensed security configuration in inactive state. The security protection method and key parameters are preserved in a compact form in context information, enabling rapid activation with reduced processing overhead.
3Quantity of substance
If security context is deleted in idle state, then memory resources are freed, but security re-establishment time increases when transitioning to connected state
Solution Approach 1:
The patent applies preliminary action by retaining essential security configuration information in context data before transitioning to idle state. When the UE needs to resume connection, the target base station can quickly retrieve these pre-stored security parameters from context information, avoiding time-consuming security re-establishment procedures while maintaining acceptable memory usage.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Embodiments of this application provide a communication method and a communications apparatus. The method includes: after receiving an RRC resume message from user equipment, determining, by a target access network device, a first user plane security protection method between the target access network device and the user equipment based on a context information obtaining response from a source access network device; determining a first user plane security key between the target access network device and the user equipment, when receiving first uplink user plane data from the user equipment, performing user plane security deprotection on the first uplink user plane data based on the first user plane security key and the first user plane security protection method, to obtain uplink user plane data; and sending the uplink user plane data. According to the embodiments of this application, user plane security in an inactive scenario can be ensured, thereby ensuring user plane data transmission security in the inactive scenario.