Wireless Service Security Using a User Plane Security Anchor

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless network security architectures face challenges in supporting additional security layers, making it difficult to add services that require security features not supported by the security function, especially in large geographic areas with multiple network domains.

Innovation Solution

A wireless network service security architecture is introduced that allows different services to establish their own security contexts independently of the non-access stratum security, using a user plane security anchor (UPSA) to provide secure communication between wireless devices and services, enabling the transport service to determine and provision the UPSA with a service key for secure access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a unified security architecture is used for all wireless services, then security management is simplified, but services requiring specialized security features cannot be supported

Engineering Contradiction:
Improvesecurity architecture complexityVSAvoidservice security feature support
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The security architecture is segmented into two independent parts: a core network security function for baseline security management, and a service-specific security function (UPSA) for specialized security features. This segmentation allows each part to operate independently, enabling services to have customized security requirements while maintaining overall architectural simplicity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The user plane security anchor (UPSA) acts as an intermediary between the core network security function and the wireless services. It receives security parameters from the core network and provides additional security processing specific to user plane services, thereby bridging the gap between unified security management and service-specific security needs.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If security contexts are established for each service independently, then service-specific security features are supported, but security management complexity increases

Engineering Contradiction:
Improveservice security feature supportVSAvoidsecurity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The architecture adds a new dimension to security management by introducing the UPSA layer between the core network and services. Instead of managing security contexts directly at the service level (which would increase complexity), the UPSA handles service-specific security in a separate dimensional layer, allowing independent security context establishment without complicating core security management.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Adaptability or versatility

If additional security layers are added to support new services, then service security requirements are met, but the security function becomes harder to extend

Engineering Contradiction:
Improveservice security feature supportVSAvoidsecurity function extendability
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The core network security function performs preliminary security setup by providing baseline security parameters to the UPSA before services require additional security processing. This preliminary action establishes a foundation that makes it easier to extend security capabilities, as new services can build upon the pre-configured security framework rather than requiring complete security function redesign.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250374039A1Wireless network transport service security
Publication Date: 2025.12.04 QUALCOMM INC
  • US20250374039A1 patent drawing
  • US20250374039A1 patent drawing
  • US20250374039A1 patent drawing

AI summary

An apparatus, method and computer-readable media are disclosed for accessing services of wireless network. For example, a process can include receiving, from a wireless device, a service session request to access a service of the wireless network; determining a user plane security anchor (UPSA) for the service and the wireless device; transmitting, to a security service of the wireless network, a request for UPSA security for the service; receiving, from the security service, a response to the request for UPSA security including information for deriving a service key; and transmitting, to the wireless device, a response to the service session request including an identifier for the UPSA and the information for deriving the service key for establishing user plane security between the UPSA and the wireless device.