Core Network Node Selecting Security Protection for 5G Services
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The evolving 3GPP standards and network structures necessitate enhanced data security protection in communications systems, which existing methods fail to optimize effectively.
Innovation Solution
A method that allows a core network node to flexibly select a network node for performing security protection based on service-specific information, including security capabilities and policies, to ensure tailored security requirements are met, decoupling security protection between UPF and access network nodes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If security protection is performed by fixed network nodes (base station or terminal device), then security implementation is simple, but security requirements of different services cannot be satisfied
Solution Approach 1:
The patent segments the security protection function from the traditional fixed network nodes (base station and terminal device) and introduces a new network node specifically dedicated to security protection. This segmentation allows different services to be assigned to different security protection nodes, satisfying service-specific security requirements while keeping each node's function specialized and manageable.
Solution Approach 2:
The patent creates a universal security protection node that can serve multiple different services with varying security requirements. This multi-functional node can be flexibly assigned to protect different services, making the security system adaptable to diverse service needs without requiring separate fixed implementations for each service type.
2Reliability
If security protection is centralized in fixed nodes, then system structure is simple, but network security cannot be enhanced flexibly
Solution Approach 1:
The patent divides the security protection function into a separate, dedicated network node, segmenting it from the traditional communication infrastructure. This segmentation enhances network security by creating specialized security nodes that can be independently managed and configured for different security levels, while the overall network structure remains organized and controllable.
3Adaptability or versatility
If different network nodes perform security protection for different services, then service-specific security is achieved, but node selection complexity increases
Solution Approach 1:
The patent enables the security protection node to autonomously determine whether to perform security protection based on service information, reducing the need for complex external selection processes. The node can self-configure and self-manage security protection for different services, simplifying operation while maintaining flexible adaptability to various service requirements.
Data Source
AI summary
The present disclosure relates to methods, apparatus, and systems for protecting data in a communications system. One example method includes obtaining, by a core network node, information associated with a service of a terminal device, and determining, by the core network node and based on the information associated with the service, a network node that is to perform security protection on data of the service.


