Method for providing security function of SDAF in 5g core network

By integrating the Security Data Analytics Function (SDAF) into the 5G core network, security functions are provided within the network, addressing the lack of dedicated security functions and enhancing security management and analysis capabilities.

WO2025121849A1PCT designated stage expired Publication Date: 2025-06-12KOOKMIN UNIV IND ACAD COOP FOUND
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2024/019619
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-06
Filing Date
2024-12-03
Publication Date
2025-06-12

AI Technical Summary

Technical Problem

Current 5G core network technologies lack a dedicated network function for security functions, and existing security mechanisms are not internalized within the core network.

Method used

The implementation of a Security Data Analytics Function (SDAF) within the 5G core network, which registers with the Network Repository Function (NRF) and Unified Data Management (UDM) to configure a security analysis environment, collects security data from multiple network functions, performs security analysis, generates security policies, and transmits these policies to requesting network functions.

Benefits of technology

SDAF enables the provision of security functions within the 5G core network, acting as a security agent to perform security analysis and policy generation, thereby enhancing the network's security capabilities and management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024019619_12062025_PF_FP_ABST
    Figure KR2024019619_12062025_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed is a method for providing a security function of an SDAF in a 5G core network. The method for providing a security function of an SDAF in a 5G core network comprises the steps of: configuring a security analysis environment by registering information of SDAF with a network repository function (NRF) and unified data management (UDM); receiving a security analysis request from an arbitrary network function (NF) existing in a core network system based on a 5G service-based architecture (SBA) identical to the SDAF; collecting security data from a plurality of network functions existing in the core network system to perform security analysis according to the security analysis request; performing security analysis by using the collected security data; generating a security policy on the basis of a security analysis result derived according to the performed security analysis; and transmitting the generated security policy to a network function requesting the security analysis to respond to the security analysis request.
Need to check novelty before this filing date? Find Prior Art

Description

How to Provide SDAF Security Functions in 5G Core Networks

[0001] The present invention relates to a method for providing a security function of SDAF in a 5G core network.

[0002]

[0003] According to the TS 23501 standard defined by 3GPP, the standardization body for mobile communications technology, 5G SBA (Service Based Architecture) is the structure of the 5G system defined by 3GPP to enable network functions of the control plane to interact with each other based on services. The network functions of SBA interact with each other using the Service Based Interface (SBI). One of the components of this 5G SBA is the Network Data Analytics Function (NWDAF), as defined by the TS 23288 standard defined by 3GPP. This analyzes (statistically or predictively) past events for network functions existing in the 5G core network and provides the results. This enables overall management and performance improvement of the 5G network.

[0004] Korean Patent No. 10-2504207 (20230222) relates to a 5G SA network PFCP-INGTP detection system and method, which can identify user equipment causing abnormal traffic by collecting and analyzing GTP-U messages in a 5G SA network.

[0005] In addition, Korean Patent Publication No. 10-2021-0037416 (20210406) relates to a device and method for detecting a specific service and analyzing service-related characteristics by utilizing NWDAF in a mobile communication system.

[0006] In addition, Korean Patent Publication No. 10-2019-0041888 (20190423) relates to a network connection and data transmission method of a terminal applied to a next-generation 5G communication system, and a method for transmitting information between a terminal and a network and a device performing the same.

[0007] In addition, Korean Patent Publication No. 10-2020-0110392 (20200923) relates to a method and network equipment for implementing a standalone security anchor function (SEAF) and an access and mobility function (AMF) in a wireless communication network.

[0008] These prior technologies (3GPP standardized technologies) consist of one or more network functions within the core network of the 5G SBA architecture, but none of them include network functions for security. Furthermore, while known technologies include mechanisms, methods, and procedures for providing security functions in 5G networks, there is no method for integrating them into the core network.

[0009]

[0010] [Prior Art Literature]

[0011] [Patent Document]

[0012] (Patent Document 0001) Republic of Korea Patent No. 10-2504207 (February 22, 2023)

[0013] (Patent Document 0002) Republic of Korea Patent Publication No. 10-2021-0037416 (April 6, 2021)

[0014] (Patent Document 0003) Republic of Korea Patent Publication No. 10-2019-0041888 (April 23, 2019)

[0015] (Patent Document 0004) Republic of Korea Patent Publication No. 10-2020-0110392 (September 23, 2020)

[0016]

[0017] The present invention provides a method for providing a security function of SDAF (Security Data Analytics Function) in a 5G core network, which enables SDAF to perform the role of a security agent in a 5G SBA (Service-Based Architecture).

[0018]

[0019] According to one aspect of the present invention, a method for providing a security function of SDAF (Security Data Analytics Function) in a 5G core network is disclosed.

[0020] A method for providing a security function of SDAF in a 5G core network according to an embodiment of the present invention includes the steps of registering information of the SDAF with a Network Repository Function (NRF) and Unified Data Management (UDM) to configure a security analysis environment, receiving a security analysis request from an arbitrary network function (NF: Network Function) existing in a core network system based on a 5G Service-Based Architecture (SBA) that is the same as the SDAF, collecting security data from a plurality of network functions existing in the core network system to perform security analysis according to the security analysis request, performing security analysis using the collected security data, generating a security policy based on a security analysis result derived according to the performed security analysis, and transmitting the generated security policy to a network function that has requested security analysis to respond to the security analysis request.

[0021] The step of configuring the above security analysis environment is performed when the SDAF first connects with the NRF in the core network system or when the information of the SDAF is updated.

[0022] The step of configuring the above security analysis environment configures the security analysis environment so that any network function (NF: Network Function) existing in the core network system can search for and select an SDAF instance when it wishes to perform security analysis through the SDAF.

[0023] The step of receiving the above security analysis request receives the security analysis request from the network function by performing a preset security analysis request reception procedure from any network function existing in the core network system.

[0024] The step of receiving the above security analysis request includes receiving a security analysis request including an identifier of a network function requesting the security analysis.

[0025] The step of receiving the above security analysis request is to request security analysis from a network function that consumes the security analysis result.

[0026] The step of collecting the above security data includes transmitting a security data collection request including the identifier of the SDAF to a plurality of network functions existing in the core network system.

[0027]

[0028] A method for providing a security function of SDAF in a 5G core network according to an embodiment of the present invention can enable SDAF (Security Data Analytics Function) to perform the role of a security agent in a 5G SBA (Service-Based Architecture).

[0029]

[0030] FIG. 1 is a diagram schematically illustrating the configuration of a 5G SBA (Service-Based Architecture)-based core network system to which SDAF (Security Data Analytics Function) is applied according to an embodiment of the present invention.

[0031] Figure 2 is a diagram showing the function of SDAF according to an embodiment of the present invention.

[0032] FIG. 3 is a diagram showing a service method in a case where SDAF according to an embodiment of the present invention is a service provider (Producer) and a service consumer (Consumer).

[0033] FIG. 4 is a flowchart schematically illustrating a method for providing security functions of SDAF in a 5G core network performed by SDAF according to an embodiment of the present invention.

[0034]

[0035] As used herein, singular expressions include plural expressions unless the context clearly dictates otherwise. In this specification, terms such as "consist of" or "include" should not be construed as necessarily including all components or steps described in the specification, and should be construed as meaning that some of the components or steps may not be included, or that additional components or steps may be further included. In addition, terms such as "unit" and "module" described in the specification mean a unit that processes at least one function or operation, which may be implemented by hardware or software, or by a combination of hardware and software.

[0036] Hereinafter, various embodiments of the present invention will be described in detail with reference to the attached drawings.

[0037] FIG. 1 is a diagram schematically illustrating the configuration of a 5G SBA (Service-Based Architecture)-based core network system to which a Security Data Analytics Function (SDAF) is applied according to an embodiment of the present invention, FIG. 2 is a diagram illustrating the function of the SDAF according to an embodiment of the present invention, FIG. 3 is a diagram illustrating a service method in the case where the SDAF according to an embodiment of the present invention is a service provider (Producer) and a service consumer (Consumer), and FIG. 4 is a flowchart schematically illustrating a method for providing a security function of the SDAF in a 5G core network performed by the SDAF according to an embodiment of the present invention. Hereinafter, a method for providing a security function of the SDAF in a 5G core network according to an embodiment of the present invention will be described with reference to FIGS. 1 to 4.

[0038] Referring to FIG. 1, a 5G SBA-based core network system may be configured to include a Security Data Analytics Function (SDAF), a Network Repository Function (NRF), a Unified Data Management (UDM), an Application Function (AF), a Network Data Analytics Function (NWDAF), a Policy Control Function (PCF), an Access and Mobility Management Function (AMF), a Session Management Function (SMF), a Unified Data Repository (UDR), a User Plane Function (UPF), a User Equipment (UE), and a gNodeB (gNB).

[0039] SDAF performs security analysis on 5G SBA-based core network systems and provides security analysis results.

[0040] Any component other than SDAF can request security analysis from SDAF, and SDAF can collect security data from components other than SDAF to derive security analysis results. SDAF responds to security analysis requests by transmitting the security analysis results derived upon request to the component that requested the analysis.

[0041] As shown in Figure 2, SDAF has three functions: data collection, security analysis, and security policy creation and enforcement.

[0042] Here, data collection is a function that collects data necessary for performing security analysis to respond to security threats occurring in the core network. It collects NF data generated from network functions (NF) such as AMF, SMF, UDM, UPF, and PCF, and collects security data such as packets generated from NF and IDS logs installed in NF.

[0043] Next, security analysis is a function to respond to security threats occurring in the core network, and it performs analysis using SIEM (Security Information & Event Management) analysis, ML (Machine Learning) analysis, and security threat database. Here, SIEM analysis performs security analysis using SIEM, a control system, as another network function, and transmits the derived analysis results in response to requests from other network functions. ML analysis performs security analysis using machine learning and transmits the derived analysis results in response to requests from other network functions. Analysis using the security threat database performs a search in the security threat database to derive security information results and transmits the derived analysis results in response to requests from other network functions in order to provide security information on data requested from the SDAF by other network functions.

[0044] Next, security policy creation and enforcement is a function to create a security response policy and enforce the created security response policy in the core network in order to respond to security threats occurring in the core network.

[0045] Referring to Figure 1, SDAF provides an Nsdaf interface and connects to a consumer network function (Consumer NF) through the Nsdaf interface. Through this, SDAF provides services to the consumer network function.

[0046] Additionally, SDAF and consumer network functions that consume SDAF services can request services and respond to them using service operations via the Nsdaf interface.

[0047] Referring to Figure 3, services can be provided in two ways: when SDAF acts as a service provider (Producer) or as a service consumer (Consumer). In Figure 3, the Policy Control Function (PCF) manages network policies, and the User Plane Function (UPF) manages user plane traffic.

[0048] For example, PCF can send a service operation requesting security analysis to SDAF using the Nsdaf interface, and receive a service operation including the security analysis results as a response from SDAF using the Nsdaf interface.

[0049] That is, SDAF receives a service operation requesting security analysis from PCF and sends a service operation requesting related data collection to UPF to provide security analysis results to PCF. SDAF receives a service operation that responds with data collection results from UPF. Based on the collected data, SDAF derives statistical results using SIEM analysis and creates security policies. SDAF sends a service operation responding to the security analysis request to PCF to provide security analysis results to PCF.

[0050] Here, UPF receives a service operation requesting data collection for security analysis from SDAF, and sends a service operation responding to the data collection request for security analysis to SDAF.

[0051] Hereinafter, with reference to FIG. 4, a method for providing a security function of SDAF in a 5G core network according to an embodiment of the present invention will be described.

[0052] At step S410, SDAF configures a security analysis environment by registering its own information with NRF (Network Repository Function) and UDM (Unified Data Management).

[0053] That is, SDAF can configure a security analysis environment so that any network function (NF: Network Function) existing in the same 5G SBA-based core network system as SDAF can search for and select an SDAF instance when it wants to perform security analysis through SDAF.

[0054] When SDAF first interfaces with NRF in a 5G SBA-based core network system or when SDAF information is updated, SDAF's security analysis environment configuration can be performed.

[0055] At step S420, the SDAF receives a security analysis request from any network function (NF) existing in the same 5G SBA-based core network system as the SDAF.

[0056] Here, the SDAF can receive a security analysis request from a network function by performing a pre-configured security analysis request reception procedure from any network function existing in the same 5G SBA-based core network system.

[0057] SDAF can receive a security analysis request that includes the identifier of the network function requesting the security analysis. Furthermore, SDAF can receive a security analysis request from the network function that consumes the security analysis results.

[0058] At step S430, the SDAF collects security data from multiple network functions existing in the same 5G SBA-based core network system to perform the requested security analysis.

[0059] The SDAF can send a security data collection request containing its identifier to multiple network functions existing in the same 5G SBA-based core network system.

[0060] At step S440, SDAF performs security analysis using the collected security data.

[0061] At step S450, SDAF generates a security policy based on the security analysis results derived from the performed security analysis.

[0062] At step S460, SDAF responds to the security analysis request by sending the generated security policy to the network function that requested the security analysis.

[0063] Meanwhile, the components of the aforementioned embodiments can be easily understood from a process perspective. That is, each component can be understood as a separate process. Furthermore, the processes of the aforementioned embodiments can be easily understood from the perspective of the device components.

[0064] In addition, the technical contents described above may be implemented in the form of program commands that can be executed through various computer means and recorded on a computer-readable medium. The computer-readable medium may include program commands, data files, data structures, etc., alone or in combination. The program commands recorded on the medium may be those specially designed and configured for the embodiments or may be known and available to those skilled in the art of computer software. Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks, and magnetic tapes, optical media such as CD-ROMs and DVDs, magneto-optical media such as floptical disks, and hardware devices specially configured to store and execute program commands, such as ROMs, RAMs, and flash memories. Examples of program commands include not only machine language codes generated by a compiler, but also high-level language codes that can be executed by a computer using an interpreter, etc. The hardware devices may be configured to operate as one or more software modules to perform the operations of the embodiments, and vice versa.

[0065] The above-described embodiments of the present invention are disclosed for the purpose of illustration, and those skilled in the art with common knowledge of the present invention will be able to make various modifications, changes, and additions within the spirit and scope of the present invention, and such modifications, changes, and additions should be considered to fall within the scope of the following patent claims.

[0066]

[0067] [National Research and Development Project Supporting This Invention]

[0068] [Project ID] 1711193276

[0069] [Assignment Number] 2021-0-00796-003

[0070] [Ministry Name] Ministry of Science and ICT

[0071] [Name of Project Management (Specialist) Agency] Information and Communications Technology Planning and Evaluation Institute

[0072] [Research Project Name] Information Protection Core Source Technology Development (R&D)

[0073] Research Project Title: 6G Autonomous Security Integrating Foundational Technology for Continuous Security Quality Assurance

[0074] [Contribution rate] 1 / 1

[0075] [Name of the project performing organization] Electronics and Telecommunications Research Institute

[0076] [Research Period] January 1, 2023 - December 31, 2023

Claims

1. In a method for providing security functions of SDAF (Security Data Analytics Function) in a 5G core network, A step for configuring a security analysis environment by registering the information of the SDAF with NRF (Network Repository Function) and UDM (Unified Data Management); A step of receiving a security analysis request from any network function (NF: Network Function) existing in a core network system based on a 5G SBA (Service-Based Architecture) identical to the above SDAF; A step of collecting security data from a plurality of network functions existing in the core network system to perform security analysis according to the above security analysis request; A step of performing security analysis using the collected security data; A step of generating a security policy based on the security analysis results derived from the security analysis performed above; and A method for providing a security function of SDAF in a 5G core network, comprising the step of transmitting the generated security policy to a network function that requested security analysis and responding to the security analysis request.

2. In paragraph 1, The steps to configure the above security analysis environment are: A method for providing a security function of SDAF in a 5G core network, characterized in that the SDAF is performed when the SDAF first connects with the NRF in the core network system or when the information of the SDAF is updated.

3. In paragraph 1, The steps to configure the above security analysis environment are: A method for providing a security function of SDAF in a 5G core network, characterized in that the security analysis environment is configured so that an SDAF instance can be searched and selected when any network function (NF: Network Function) existing in the core network system wishes to perform a security analysis through the SDAF.

4. In paragraph 1, The step of receiving the above security analysis request is: A method for providing a security function of SDAF in a 5G core network, characterized in that a security analysis request is received from a network function by performing a reception procedure of a preset security analysis request from any network function existing in the core network system.

5. In paragraph 1, The step of receiving the above security analysis request is: A method for providing a security function of SDAF in a 5G core network, characterized by receiving a security analysis request including an identifier of a network function requesting the above security analysis.

6. In paragraph 1, The step of receiving the above security analysis request is: A method for providing a security function of SDAF in a 5G core network, characterized in that a security analysis is requested from a network function that consumes the above security analysis results.

7. In paragraph 1, The steps for collecting the above security data are: A method for providing a security function of SDAF in a 5G core network, characterized by transmitting a security data collection request including an identifier of the SDAF to a plurality of network functions existing in the core network system.

Citation Information

Patent Citations

  • Long tunnel scale model fire test method

    KR1020250069052A

  • Security management in communication systems between security edge protection proxy elements

    US20190253885A1

  • Injecting analytics into Network Repository Function (NRF) for automated management of 5G core

    US20220345913A1

  • Cybersecurity system for common interface of service-based architecture of a wireless telecommunications network

    US20220377103A1

  • KR20230018457A