Cellular Network Function Port-Based Security Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cellular communication systems, such as 5G systems, face security risks due to unprotected communication at boundary interfaces, which can lead to attacks like rogue master attacks, spoofing, packet interception, and Layer2/Layer3 Denial of Service (DoS) attacks.

Innovation Solution

The implementation of a port-based network access control standard, such as IEEE 802.1X, and a port-based medium access security standard, such as IEEE 802.1AE, is configured through configuration information received by network functions within the cellular communication system. This configuration enables secure operation at boundary interfaces, protecting against unauthorized access and data manipulation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If port-based network access control and medium access security standards are implemented, then security against unauthorized access and data manipulation is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security implementation into separate network functions (NFs) that can independently configure and enforce security policies. Each NF manages its own security parameters, allowing distributed security control without requiring a single complex centralized system. This segmentation reduces overall system complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent utilizes parameter changes by allowing network functions to dynamically adjust security parameters such as authentication methods, encryption keys, and access control lists based on configuration information. This enables the system to adapt security measures to different network conditions and threat levels, improving security effectiveness without requiring permanent complex configurations.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If configuration information is received and processed by network functions, then secure integration with other networks is improved, but loss of time increases

Engineering Contradiction:
Improvesecure integrationVSAvoidconfiguration processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-configuring network functions with security parameters and authentication information before actual communication occurs. Configuration information is received and processed in advance, allowing security measures to be established before data transmission begins. This eliminates the need for time-consuming security setup during active communication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Network functions perform self-configuration by automatically receiving and processing configuration information without requiring manual intervention or complex setup procedures. The system enables self-service security initialization where each NF independently configures its security parameters based on received configuration data, reducing processing time and improving integration efficiency.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3975523B1Enhanced security mechanisms for cellular communication systems
Publication Date: 2025.06.11 NOKIA TECHNOLOGIES OY
  • EP3975523B1 patent drawingFigure 1
  • EP3975523B1 patent drawingFigure 2a~2b
  • EP3975523B1 patent drawingFigure 3a~3b

AI summary

According to an example aspect of the present invention, there is provided a method comprising, receiving, by a network function (140) in a cellular communication system (100), configuration information required to initialize at least one other network function (102, 104, 108) to operate according to a port-based network access control standard and a port-based medium access security standard, wherein the network function (140) is configured to provide time sensitive networking or communications, and the configuration information comprises a storage format of the port-based network access control standard and a storage format of the port-based medium access security standard and configuring the at least one other network function (102, 104, 108) to operate according to the port-based network control standard and the port-based medium access security standard based on the configuration information.