Core Network Node Selecting Security Protection for 5G Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The evolving 3GPP standards and network structures necessitate enhanced data security protection in communications systems, which existing methods fail to optimize effectively.

Innovation Solution

A method that allows a core network node to flexibly select a network node for performing security protection based on service-specific information, including security capabilities and policies, to ensure tailored security requirements are met, decoupling security protection between UPF and access network nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If security protection is performed by fixed network nodes (base station or terminal device), then security implementation is simple, but security requirements of different services cannot be satisfied

Engineering Contradiction:
Improveservice-specific security requirement satisfactionVSAvoidsecurity protection implementation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the security protection function from the traditional fixed network nodes (base station and terminal device) and introduces a new network node specifically dedicated to security protection. This segmentation allows different services to be assigned to different security protection nodes, satisfying service-specific security requirements while keeping each node's function specialized and manageable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal security protection node that can serve multiple different services with varying security requirements. This multi-functional node can be flexibly assigned to protect different services, making the security system adaptable to diverse service needs without requiring separate fixed implementations for each service type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If security protection is centralized in fixed nodes, then system structure is simple, but network security cannot be enhanced flexibly

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the security protection function into a separate, dedicated network node, segmenting it from the traditional communication infrastructure. This segmentation enhances network security by creating specialized security nodes that can be independently managed and configured for different security levels, while the overall network structure remains organized and controllable.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If different network nodes perform security protection for different services, then service-specific security is achieved, but node selection complexity increases

Engineering Contradiction:
Improveflexible node selectionVSAvoidnode selection process
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent enables the security protection node to autonomously determine whether to perform security protection based on service information, reducing the need for complex external selection processes. The node can self-configure and self-manage security protection for different services, simplifying operation while maintaining flexible adaptability to various service requirements.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11140545B2Method, apparatus, and system for protecting data
Publication Date: 2021.10.05 HUAWEI TECH CO LTD
  • US11140545B2 patent drawing
  • US11140545B2 patent drawing
  • US11140545B2 patent drawing

AI summary

The present disclosure relates to methods, apparatus, and systems for protecting data in a communications system. One example method includes obtaining, by a core network node, information associated with a service of a terminal device, and determining, by the core network node and based on the information associated with the service, a network node that is to perform security protection on data of the service.