5G User-Plane Security Policies for Precision Time Protocol Messages

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Communication networks face challenges in ensuring the security and integrity of precision time protocol messages, which are crucial for time-sensitive networking, as they are vulnerable to tampering and unauthorized access, affecting the reliability of timekeeping and synchronization.

Innovation Solution

A network apparatus sets a security policy for user plane transfer of precision time protocol messages, enforcing integrity and confidentiality protection, and instructs network nodes to implement this policy, particularly in 5G systems acting as bridges between time-aware systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If precision time protocol messages are transmitted in the user plane without security policies, then transmission speed and simplicity are improved, but security and integrity of timekeeping are compromised

Engineering Contradiction:
Improveintegrity of time protocol messagesVSAvoidsecurity policy implementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by establishing security policies before precision time protocol messages are transmitted in the user plane. The network node configures integrity protection and confidentiality protection mechanisms in advance, so that when time-sensitive messages are transmitted, the security measures are already in place without adding real-time processing complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary security policy mechanism that mediates between the user plane transmission requirements and security requirements. The security policy acts as an intermediate layer that protects time protocol messages without requiring direct modification of the transmission path or message format.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security policies are enforced on user plane time protocol messages, then security and integrity are improved, but processing overhead and latency increase

Engineering Contradiction:
Improveconfidentiality of time protocol messagesVSAvoidmessage transmission latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies local quality by selectively applying security policies only to precision time protocol messages in the user plane, rather than all traffic. The network node identifies time-sensitive messages and applies integrity and confidentiality protection specifically to these messages, leaving other traffic unaffected.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes parameters by adjusting security policy configurations based on traffic type and sensitivity. Different integrity protection levels and confidentiality settings are applied depending on the specific time protocol message requirements, optimizing the balance between security and latency.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If existing communication network mechanisms are used without time-awareness, then general communication flexibility is maintained, but time-sensitive networking requirements are not met

Engineering Contradiction:
Improvecapability to support time-sensitive networkingVSAvoidtime-aware network node complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing security policy mechanisms that can handle both general communication traffic and time-sensitive precision time protocol messages through a unified framework. The same security policy infrastructure serves multiple purposes, reducing the need for separate dedicated systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces dynamics by enabling network nodes to adaptively adjust security policy configurations based on real-time traffic characteristics and time-sensitivity requirements. The system can dynamically configure integrity protection and confidentiality settings according to the specific needs of different time protocol messages.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12418569B2Network management
Publication Date: 2025.09.16 NOKIA TECHNOLOGIES OY
  • US12418569B2 patent drawing
  • US12418569B2 patent drawing
  • US12418569B2 patent drawing

AI summary

The apparatus includes a memory configured to store security information, and at least one processing core, configured to generate the security information by defining a security policy concerning user plane transfer of precision time protocol messages, and to instruct at least one network node to implement the security policy by transmitting the security information to the at least one network node.