Application Verification for Secure Network Slice PDU Sessions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The 3GPP standard does not limit the coding of the OSAppId value, allowing counterfeit applications to potentially misuse specific network slices, compromising network security.

Innovation Solution

An electronic device verifies applications using identification and verification information to establish PDU sessions only when the OSAppId values match, preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the OSAppId value coding is not limited according to 3GPP standard, then application identification flexibility is improved, but network security deteriorates due to counterfeit applications

Engineering Contradiction:
Improveapplication identification flexibilityVSAvoidnetwork security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-configuring verification information (hash values, digital signatures, or certificates) in the URSP rule before the application requests network access. The electronic device performs verification of the application's OSAppId against this pre-stored information, enabling security checks to be conducted in advance rather than reacting to potential threats after they occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces verification information as an intermediary element between the application identifier (OSAppId) and the network slice selection process. This intermediary layer includes hash values, digital signatures, or certificates that mediate the verification process, allowing the system to validate application authenticity without directly exposing or limiting the OSAppId coding flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If verification information is added to URSP rule, then network security is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidURSP rule structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing a verification information structure that can serve multiple functions within the URSP rule framework. The same verification mechanism (hash, digital signature, or certificate) can validate different application identifiers across various network slice scenarios, reducing the need for separate verification systems for each case and thereby managing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent manages complexity through parameter changes by allowing the verification method to be selected or configured based on security requirements. The system can adjust the verification parameter type (hash algorithm, signature scheme, or certificate validation) without fundamentally changing the URSP rule structure, enabling flexible security management while maintaining a consistent framework.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12549637B2Electronic device establishing data session with network slice, and method for operating same
Publication Date: 2026.02.10 SAMSUNG ELECTRONICS CO LTD
  • US12549637B2 patent drawing
  • US12549637B2 patent drawing
  • US12549637B2 patent drawing

AI summary

An electronic device includes a memory and a processor configured to: store, in the memory, relationship information comprising identification information of at least one application, verification information for verification of each of the at least one application, and information for establishing a protocol data unit (PDU) session for each of the at least one application; confirm a first value on the basis of a first application having first identification information included in the relationship information; confirm, by using the relationship information, a second value on the basis of verification information corresponding to the first identification information; establish, on the basis of the first value and the second value being the same, a first PDU session by using the information for establishing the PDU session corresponding to the first application; and transmit or receive data related to the first application by using the first PDU session.