Core Network Trustworthiness Verification via Trusted Certificates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The 3GPP lacks dedicated security measures for core network elements and signaling exchanges, leading to security risks such as network hijacking and data leakage, which compromise the integrity of network element information and user privacy.
Innovation Solution
A communication method integrated with trustworthiness measurement, where network elements verify the trustworthiness of platforms through registration requests, authorization grants, and service requests, using trusted certificates and attestation results to ensure secure communication and authentication processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If no dedicated security measures are implemented for core network elements, then the system maintains simplicity and low operational overhead, but security reliability deteriorates leading to network hijacking and data leakage risks
Solution Approach 1:
The patent implements preliminary security verification by requiring network elements to present trusted certificates during registration with the network repository function. The NRF verifies these certificates before allowing registration, establishing security credentials in advance. This preliminary action ensures that only trusted network elements can join the network, preventing security issues before they occur rather than relying on complex ongoing security measures.
2Reliability
If trustworthiness verification is implemented through certificate validation, then security reliability improves by preventing network hijacking, but the complexity of authentication processes increases
Solution Approach 1:
The patent introduces a network repository function as an intermediary that centralizes the certificate verification process. Instead of each network element directly verifying certificates with every other element (which would be complex), the NRF acts as a trusted mediator that validates certificates and maintains a repository of trusted network elements. This simplifies the authentication process while maintaining strong security verification.
3Reliability
If security verification procedures are added to the communication process, then security reliability improves by preventing malicious network elements, but processing time and operational efficiency decrease
Solution Approach 1:
The patent performs security verification during the initial registration phase rather than during every subsequent communication interaction. Once a network element's certificate is verified and it is registered with the NRF, the security credentials are established in advance. This allows subsequent communications to proceed more efficiently without repeating the full verification process, thus maintaining security while improving operational efficiency.
Data Source
AI summary
A method includes: a network function service consumer sends a service request message, where the service request message is used to request to obtain a service provided by a network function service provider. The network function service consumer receives a service response message, where the service response message indicates whether the service request message is accepted, and further indicates a result of trustworthiness verification of the network function service consumer. The method helps the network function service provider verify, before providing the network service, an identity of the network function service consumer and determine whether the network function service consumer is trusted, to help improve security of communication between core network elements and improve security of a core network device.


