SDAF communication device for providing security function in 5g core network
The SDAF communication device addresses the lack of security functions in 5G core networks by providing a comprehensive security analysis and policy enforcement mechanism through multiple communication interfaces, effectively enhancing network security.
Patent Information
- Application Number
- PCT/KR2024/019615
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-06
- Filing Date
- 2024-12-03
- Publication Date
- 2025-06-12
AI Technical Summary
Existing 5G core network technologies lack a dedicated network function for security functions and do not have a communication interface to provide security functions within the 5G network.
A communication device for the Security Data Analytics Function (SDAF) is introduced, which provides a security function in the 5G core network. This device includes multiple communication interfaces for configuring a security analysis environment, collecting network and security data, performing SIEM, ML, and security threat DB analyses, and creating and enforcing security policies.
The SDAF communication device effectively enhances the security of the 5G core network by providing a comprehensive security analysis and policy enforcement mechanism, addressing the lack of security functions in existing 5G network architectures.
Smart Images

Figure KR2024019615_12062025_PF_FP_ABST
Abstract
Description
SDAF's communication device that provides security functions in the 5G core network
[0001] The present invention relates to a communication device of SDAF that provides a security function in a 5G core network.
[0002]
[0003] According to the TS 23501 standard defined by 3GPP, the standardization body for mobile communications technology, 5G SBA (Service Based Architecture) is the structure of the 5G system defined by 3GPP to enable network functions of the control plane to interact with each other based on services. The network functions of SBA interact with each other using the Service Based Interface (SBI). One of the components of this 5G SBA is the Network Data Analytics Function (NWDAF), as defined by the TS 23288 standard defined by 3GPP. This analyzes (statistically or predictively) past events for network functions existing in the 5G core network and provides the results. This enables overall management and performance improvement of the 5G network.
[0004] Korean Patent No. 10-2504207 (20230222) relates to a 5G SA network PFCP-INGTP detection system and method, which can identify user equipment causing abnormal traffic by collecting and analyzing GTP-U messages in a 5G SA network.
[0005] In addition, Korean Patent Publication No. 10-2021-0037416 (20210406) relates to a device and method for detecting a specific service and analyzing service-related characteristics by utilizing NWDAF in a mobile communication system.
[0006] In addition, Korean Patent Publication No. 10-2019-0041888 (20190423) relates to a network connection and data transmission method of a terminal applied to a next-generation 5G communication system, and a method for transmitting information between a terminal and a network and a device performing the same.
[0007] In addition, Korean Patent Publication No. 10-2020-0110392 (20200923) relates to a method and network equipment for implementing a standalone security anchor function (SEAF) and an access and mobility function (AMF) in a wireless communication network.
[0008] These prior technologies (3GPP standardized technologies) consist of one or more network functions within the core network of the 5G SBA architecture, but none of them include network functions for security. Furthermore, these already known technologies lack communication interfaces for providing security functions in 5G networks.
[0009]
[0010] [Prior Art Literature]
[0011] [Patent Document]
[0012] (Patent Document 0001) Republic of Korea Patent No. 10-2504207 (February 22, 2023)
[0013] (Patent Document 0002) Republic of Korea Patent Publication No. 10-2021-0037416 (April 6, 2021)
[0014] (Patent Document 0003) Republic of Korea Patent Publication No. 10-2019-0041888 (April 23, 2019)
[0015] (Patent Document 0004) Republic of Korea Patent Publication No. 10-2020-0110392 (September 23, 2020)
[0016]
[0017] The present invention provides a communication device of an SDAF that provides a security function in a 5G core network having a communication interface with a network function (NF) for providing a security function in a 5G SBA (Service-Based Architecture)-based core network system.
[0018]
[0019] According to one aspect of the present invention, a communication device of a Security Data Analytics Function (SDAF) that provides a security function in a 5G core network is disclosed.
[0020] A communication device of an SDAF that provides a security function in a 5G core network according to an embodiment of the present invention includes a first communication interface that links with an SBA (Service-Based Architecture) interface to configure a security analysis environment by registering the SDAF's own information with an NRF (Network Repository Function) and UDM (Unified Data Management), a second communication interface for collecting NF (Network Function) data and security data from a plurality of network functions existing in a 5G SBA-based core network system identical to the SDAF, a third communication interface for SIEM (Security Information & Event Management) analysis, ML (Machine Learning) analysis, and analysis using a security threat DB, and a fourth communication interface for creating and enforcing a security policy.
[0021] The above first communication interface supports the SDAF to configure a security analysis environment so that when any network function (NF: Network Function) existing in the core network system wishes to request a security analysis function through the SDAF, the SDAF can search for and select an SDAF instance.
[0022] The above first communication interface supports the configuration of the security analysis environment of the SDAF when the SDAF first interfaces with the NRF in the core network system or when the information of the SDAF is updated, and performs a request and response for interface with the SBA interface using a request / response method.
[0023] The second communication interface performs requests and responses to collect NF data and security data using the request / response and subscribe / notify methods with AMF (Access and Mobility Management Function), SMF (Session Management Function), UDM (Unified Data Management), UPF (User Plane Function), and PCF (Policy Control Function).
[0024] The third communication interface receives a security analysis request from any network function (NF: Network Function) existing in the core network system, performs the requested security analysis, and provides the generated security analysis result.
[0025] The above third communication interface performs requests and responses for SIEM analysis, ML analysis, and analysis using a security threat DB using the request / response and subscribe / notify methods of AMF, SMF, UDM, UPF, and PCF.
[0026] The above fourth communication interface supports transmitting a security policy generated by receiving a request from any network function existing in the core network system so that it is applied and enforced in the core network system.
[0027] The above-mentioned fourth communication interface performs requests and responses for security policy creation and enforcement using the Request / Response and Subscribe / Notify methods in AMF, SMF, UDM, UPF, and PCF.
[0028]
[0029] The communication device of the SDAF that provides a security function in a 5G core network according to an embodiment of the present invention may be equipped with a communication interface with a network function (NF) for providing a security function in a 5G SBA (Service-Based Architecture)-based core network system.
[0030]
[0031] FIG. 1 is a diagram schematically illustrating the configuration of a 5G SBA (Service-Based Architecture)-based core network system to which SDAF (Security Data Analytics Function), which provides a security function in a 5G core network according to an embodiment of the present invention, is applied.
[0032] Figure 2 is a drawing showing an example of applying the Nnrf interface among the 5G SBA interfaces (SBI).
[0033] Figure 3 is a diagram showing an example of applying Namf, Nsmf, Nudm, Nupf, and Npcf interfaces among 5G SBA interfaces (SBI).
[0034] Figure 4 is a diagram showing an example of applying the Nsdaf interface among the 5G SBA interfaces (SBI).
[0035]
[0036] As used herein, singular expressions include plural expressions unless the context clearly dictates otherwise. In this specification, terms such as "consist of" or "include" should not be construed as necessarily including all components or steps described in the specification, and should be construed as meaning that some of the components or steps may not be included, or that additional components or steps may be further included. In addition, terms such as "unit" and "module" described in the specification mean a unit that processes at least one function or operation, which may be implemented by hardware or software, or by a combination of hardware and software.
[0037] Hereinafter, various embodiments of the present invention will be described in detail with reference to the attached drawings.
[0038]
[0039] FIG. 1 is a diagram schematically illustrating the configuration of a 5G Service-Based Architecture (SBA)-based core network system to which a Security Data Analytics Function (SDAF) providing a security function in a 5G core network according to an embodiment of the present invention is applied, FIG. 2 is a diagram illustrating an example of applying the Nnrf interface among 5G SBA interfaces (SBIs), FIG. 3 is a diagram illustrating an example of applying the Namf, Nsmf, Nudm, Nupf, and Npcf interfaces among 5G SBA interfaces (SBIs), and FIG. 4 is a diagram illustrating an example of applying the Nsdaf interface among 5G SBA interfaces (SBIs). Hereinafter, SDAF providing a security function in a 5G core network according to an embodiment of the present invention will be described with reference to FIGS. 1 to 4.
[0040] Referring to FIG. 1, a 5G SBA-based core network system may be configured to include a Security Data Analytics Function (SDAF), a Network Repository Function (NRF), a Unified Data Management (UDM), an Application Function (AF), a Network Data Analytics Function (NWDAF), a Policy Control Function (PCF), an Access and Mobility Management Function (AMF), a Session Management Function (SMF), a Unified Data Repository (UDR), a User Plane Function (UPF), a User Equipment (UE), and a gNodeB (gNB).
[0041] SDAF performs security analysis on 5G SBA-based core network systems and provides security analysis results.
[0042] Any component other than SDAF can request security analysis from SDAF, and SDAF can collect security data from components other than SDAF to derive security analysis results. SDAF responds to security analysis requests by transmitting the security analysis results derived upon request to the component that requested the analysis.
[0043] SDAF has three functions: data collection, security analysis, and security policy creation and enforcement.
[0044] Here, data collection is a function that collects data necessary for performing security analysis to respond to security threats occurring in the core network. It collects NF data generated from network functions (NF) such as AMF, SMF, UDM, UPF, and PCF, and collects security data such as packets generated from NF and IDS logs installed in NF.
[0045] Next, security analysis is a function to respond to security threats occurring in the core network, and it performs analysis using SIEM (Security Information & Event Management) analysis, ML (Machine Learning) analysis, and security threat database. Here, SIEM analysis performs security analysis using SIEM, a control system, as another network function, and transmits the derived analysis results in response to requests from other network functions. ML analysis performs security analysis using machine learning and transmits the derived analysis results in response to requests from other network functions. Analysis using the security threat database performs a search in the security threat database to derive security information results and transmits the derived analysis results in response to requests from other network functions in order to provide security information on data requested from the SDAF by other network functions.
[0046] Next, security policy creation and enforcement is a function to create a security response policy and enforce the created security response policy in the core network in order to respond to security threats occurring in the core network.
[0047] Referring to FIG. 2, SDAF becomes a service consumer and NRF becomes a service provider. SDAF can use the Nnrf interface among the 5G SBA interfaces (SBI) to request SBA interface linkage to NRF and receive a linkage completion response from NRF.
[0048] That is, SDAF is a communication interface for interworking with the SBA interface, and can include one communication interface using the request / response method.
[0049] Referring to FIG. 3, SDAF becomes a service consumer, and AMF, SMF, UDM, UPF, and PCF become service providers. SDAF can use the Namf interface, Nsmf interface, Nudm interface, Nupf interface, and Npcf interface among the 5G SBA interfaces (SBIs) to request collection of NF (Network Function) data and security data from AMF, SMF, UDM, UPF, and PCF, respectively, and receive a response.
[0050] That is, SDAF is a communication interface for collecting NF data and security data, and can include 24 communication interfaces using the Request / Response and Subscribe / Notify methods.
[0051] Referring to FIG. 4, AMF, SMF, UDM, UPF, and PCF become service consumers, and SDAF becomes a service provider, so that AMF, SMF, UDM, UPF, and PCF can transmit a collection completion response to a collection request for NF data and security data to SDAF using the Nsdaf interface.
[0052] That is, SDAF is a communication interface for collecting NF data and security data, and can include four communication interfaces using the Request / Response and Subscribe / Notify methods.
[0053] In addition, referring to FIG. 4, SDAF can perform a security analysis completion response to a security analysis request from AMF, SMF, UDM, UPF, and PCF using the Nsdaf interface for SIEM (Security Information & Event Management) analysis, ML (Machine Learning) analysis, and analysis using a security threat DB.
[0054] That is, SDAF is a communication interface for SIEM analysis, ML analysis, and analysis using a security threat DB, and can include two communication interfaces using the Request / Response and Subscribe / Notify methods.
[0055] In addition, referring to FIG. 4, SDAF can perform a security policy creation and enforcement completion response to a security policy creation and enforcement request of AMF, SMF, UDM, UPF, and PCF using the Nsdaf interface for security policy creation and enforcement.
[0056] That is, SDAF is a communication interface for creating and enforcing security policies, and can include 14 communication interfaces using the Request / Response and Subscribe / Notify methods.
[0057] In this way, the SDAF can be configured to include a first communication interface that links with the SBA interface to configure a security analysis environment by registering the SDAF's own information with the Network Repository Function (NRF) and Unified Data Management (UDM), a second communication interface for collecting NF data and security data from multiple network functions existing in the same 5G SBA-based core network system as the SDAF, a third communication interface for SIEM analysis, ML analysis, and analysis using a security threat DB, and a fourth communication interface for creating and enforcing security policies.
[0058] Here, the first communication interface can support SDAF to configure a security analysis environment so that any network function (NF) existing in the same 5G SBA-based core network system as SDAF can search for and select an SDAF instance when requesting a security analysis function through SDAF.
[0059] Additionally, the first communication interface supports the configuration of the SDAF's security analysis environment when the SDAF first interfaces with the NRF in a 5G SBA-based core network system or when the SDAF's information is updated, and can perform requests and responses for interfacing with the SBA interface using a request / response method.
[0060] And, the second communication interface can perform requests and responses to collect NF data and security data using the request / response and subscribe / notify methods with AMF, SMF, UDM, UPF, and PCF.
[0061] In addition, the third communication interface can support receiving a security analysis request from any network function (NF: Network Function) existing in the same 5G SBA-based core network system as the SDAF, performing the requested security analysis, and providing the generated security analysis result.
[0062] Additionally, the third communication interface can perform requests and responses for SIEM analysis, ML analysis, and analysis using a security threat DB using the request / response and subscribe / notify methods of AMF, SMF, UDM, UPF, and PCF.
[0063] In addition, the fourth communication interface can support receiving a request from any network function existing in the same 5G SBA-based core network system as the SDAF and transmitting the generated security policy so that it is applied and enforced in the core network system.
[0064] Additionally, the fourth communication interface can perform requests and responses for security policy creation and enforcement using the Request / Response and Subscribe / Notify methods with AMF, SMF, UDM, UPF, and PCF.
[0065] Meanwhile, the components of the aforementioned embodiments can be easily understood from a process perspective. That is, each component can be understood as a separate process. Furthermore, the processes of the aforementioned embodiments can be easily understood from the perspective of the device components.
[0066] In addition, the technical contents described above may be implemented in the form of program commands that can be executed through various computer means and recorded on a computer-readable medium. The computer-readable medium may include program commands, data files, data structures, etc., alone or in combination. The program commands recorded on the medium may be those specially designed and configured for the embodiments or may be known and available to those skilled in the art of computer software. Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks, and magnetic tapes, optical media such as CD-ROMs and DVDs, magneto-optical media such as floptical disks, and hardware devices specially configured to store and execute program commands, such as ROMs, RAMs, and flash memories. Examples of program commands include not only machine language codes generated by a compiler, but also high-level language codes that can be executed by a computer using an interpreter, etc. The hardware devices may be configured to operate as one or more software modules to perform the operations of the embodiments, and vice versa.
[0067] The above-described embodiments of the present invention are disclosed for the purpose of illustration, and those skilled in the art with common knowledge of the present invention will be able to make various modifications, changes, and additions within the spirit and scope of the present invention, and such modifications, changes, and additions should be considered to fall within the scope of the following patent claims.
[0068]
[0069] [National Research and Development Project Supporting This Invention]
[0070] [Project ID] 1711193276
[0071] [Assignment Number] 2021-0-00796-003
[0072] [Ministry Name] Ministry of Science and ICT
[0073] [Name of Project Management (Specialist) Agency] Information and Communications Technology Planning and Evaluation Institute
[0074] [Research Project Name] Information Protection Core Source Technology Development (R&D)
[0075] Research Project Title: 6G Autonomous Security Integrating Foundational Technology for Continuous Security Quality Assurance
[0076] [Contribution rate] 1 / 1
[0077] [Name of the project performing organization] Electronics and Telecommunications Research Institute
[0078] [Research Period] January 1, 2023 - December 31, 2023
Claims
In a communication device of SDAF (Security Data Analytics Function) that provides security functions in a 1.5G core network, A first communication interface that links with the SBA (Service-Based Architecture) interface to configure a security analysis environment by registering the SDAF's own information with NRF (Network Repository Function) and UDM (Unified Data Management); A second communication interface for collecting NF (Network Function) data and security data from multiple network functions existing in a 5G SBA-based core network system identical to the above SDAF; Third communication interface for SIEM (Security Information & Event Management) analysis, ML (Machine Learning) analysis, and analysis using security threat DB; and A communication device of SDAF providing security functions in a 5G core network including a fourth communication interface for generating and enforcing security policies.
2. In paragraph 1, A communication device of an SDAF that provides a security function in a 5G core network, characterized in that the first communication interface supports the SDAF to configure a security analysis environment so that the SDAF can search for and select an SDAF instance when any network function (NF: Network Function) existing in the core network system requests a security analysis function through the SDAF.
3. In paragraph 1, The above first communication interface is a communication device of an SDAF that provides a security function in a 5G core network, characterized in that it supports the configuration of a security analysis environment of the SDAF when the SDAF first interfaces with the NRF in the core network system or when the information of the SDAF is updated, and performs a request and response for interworking with the SBA interface using a request / response method.
4. In paragraph 1, The second communication interface is a communication device of SDAF that provides a security function in a 5G core network, characterized in that it performs requests and responses for collecting NF data and security data using a request / response and subscribe / notify method with an AMF (Access and Mobility Management Function), a SMF (Session Management Function), a UDM (Unified Data Management), an UPF (User Plane Function), and a PCF (Policy Control Function).
5. In paragraph 1, A communication device of an SDAF providing a security function in a 5G core network, characterized in that the third communication interface supports receiving a security analysis request from any network function (NF: Network Function) existing in the core network system, performing the requested security analysis, and providing the generated security analysis result.
6. In paragraph 1, The above third communication interface is a communication device of SDAF that provides security functions in a 5G core network, characterized in that it performs requests and responses for SIEM analysis, ML analysis, and analysis using a security threat DB using the request / response and subscribe / notify methods of AMF, SMF, UDM, UPF, and PCF.
7. In paragraph 1, A communication device of SDAF providing a security function in a 5G core network, characterized in that the fourth communication interface supports transmitting a security policy generated by receiving a request from any network function existing in the core network system so that it is applied and implemented in the core network system.
8. In paragraph 1, The above fourth communication interface is a communication device of SDAF that provides a security function in a 5G core network, characterized in that it performs requests and responses for creating and enforcing security policies using the Request / Response and Subscribe / Notify methods with AMF, SMF, UDM, UPF, and PCF.
Citation Information
Patent Citations
Long tunnel scale model fire test method
KR1020250069052A
Security management in communication systems between security edge protection proxy elements
US20190253885A1
Injecting analytics into Network Repository Function (NRF) for automated management of 5G core
US20220345913A1
Cybersecurity system for common interface of service-based architecture of a wireless telecommunications network
US20220377103A1
KR20230018457A