5G UE Network Slice Security via URSP Virtualization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G network slicing technologies lack effective security protection at the user equipment (UE) level, leading to potential data leakage or infiltration between network slices.

Innovation Solution

The proposed solution extends the 5G UE Route Selection Policy (URSP) with additional security descriptors, allowing the UE to bind applications to virtualization containers and establish secure tunnels, thereby segregating traffic and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If 5G network slicing is implemented without additional security measures, then network functionality and application support are improved, but security protection between network slices deteriorates leading to potential data leakage

Engineering Contradiction:
Improvenetwork slicing functionalityVSAvoiddata security between slices
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies segmentation by introducing virtualization containers that divide the UE into isolated execution environments. Each secure application is confined to its own container, preventing unauthorized access between applications and network slices. This segmentation ensures that even if one slice is compromised, the isolation prevents lateral movement to other slices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary security mechanism consisting of security descriptors and virtualization container management. This intermediary layer sits between the application and the network slice, enforcing security policies and controlling access. The security descriptors act as mediators that verify and authorize communication between applications and their designated network slices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security descriptors and virtualization containers are added to URSP, then security protection between network slices is improved, but device complexity increases

Engineering Contradiction:
Improvedata security between slicesVSAvoidUE security mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent achieves universality by extending the existing URSP framework to handle multiple security functions. The same URSP mechanism that previously handled route selection now also manages security descriptor evaluation, virtualization container selection, and PDU session binding. This multi-functionality reduces the need for separate dedicated security systems while maintaining comprehensive protection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent applies nested doll by creating hierarchical nesting of security structures: security descriptors are nested within URSP rules, virtualization containers are nested within the UE architecture, and PDU sessions are nested within network slices. This nested structure allows complex security functionality to be organized in manageable layers, reducing overall system complexity through structured composition.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS12219361B25G network slice device security protection
Publication Date: 2025.02.04 T MOBILE INNOVATIONS LLC
  • US12219361B2 patent drawing
  • US12219361B2 patent drawing
  • US12219361B2 patent drawing

AI summary

A method of user equipment (UE) implemented network slice security protection is disclosed. The method comprises the UE receiving a request to initialize an application, querying a UE Route Selection Policy (URSP) stored on the UE, and receiving traffic descriptors and security descriptors in response to the querying. The traffic descriptors identify a network slice for the application. The security descriptors comprise a security flag and a virtualization container ID. The method also comprises the UE initiating the application within a virtualization container corresponding to the virtualization container ID based on the security flag indicating that the network slice is secure and binding traffic for the application in the virtualization container to a PDU session based on the traffic descriptors. The method further comprises communicating, by the application executing within the virtualization container, with a core network over the PDU session via the network slice bound to the virtualization container.