5G Session Management Dynamic Security Policy Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G network security management systems face challenges in efficiently managing cryptographic protection for IoT devices, particularly in IoT devices with long battery life, where fine-grained security policies are difficult to configure and manage due to scalability issues and high computational costs.

Innovation Solution

A method in a session management function of a 5G system that allows user equipment to communicate with a data network either with or without cryptographic protection, based on an indication received from the data network, which can specify the need for integrity protection and encryption, thereby enabling dynamic security policy selection on a per-session basis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic protection (integrity protection and encryption) is applied in 5G networks, then security is improved, but battery consumption and computational cost increase

Engineering Contradiction:
ImprovesecurityVSAvoidbattery consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements dynamic security policy selection where the network can indicate different security requirements (integrity protection only, encryption only, both, or neither) on a per-PDU session basis. This allows the system to adapt cryptographic protection levels dynamically rather than applying fixed protection to all sessions, reducing unnecessary computational overhead and battery consumption for sessions that don't require full cryptographic protection.

Inventive Principle:
Principle #15Dynamics

2Manufacturing precision

If fine-grained security policies are configured per data network, then security management precision is improved, but device complexity and scalability worsen

Engineering Contradiction:
Improvesecurity policy granularityVSAvoidpolicy configuration complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary mechanism where the network provides security policy indications to the UE during authentication. The network acts as a mediator that dynamically communicates security requirements to the UE, eliminating the need for the UE to store and manage complex local security policies for each data network. This reduces device complexity while maintaining fine-grained security control through network-driven policy distribution.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If static security policies are configured in the SMF, then ease of operation is improved, but adaptability worsens

Engineering Contradiction:
Improvepolicy configuration simplicityVSAvoidsecurity policy flexibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent transforms static security policies into dynamic indicators that the network can adjust in real-time. Instead of configuring fixed security policies in the SMF, the system uses dynamic security policy indications sent during authentication, allowing the network to adapt security requirements based on current session needs, data network characteristics, and security conditions without requiring manual policy reconfiguration.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11689579B2Method and apparatus for security management in 5G networks
Publication Date: 2023.06.27 NOKIA TECHNOLOGIES OY
  • US11689579B2 patent drawing
  • US11689579B2 patent drawing

AI summary

A session management function of a 5G system receives information that a secondary authentication is to be done for a given user equipment for authorising user equipment to use a data network; and responsively to the received information, communicates with the data network and receives from the data network an indication; and allows a 5G access to the user equipment so that the user equipment can communicate with the data network according to the indication either without cryptographic protection or with cryptographic protection depending on the indication.