5G DS-TT Authentication via Transparent Wireless Forwarding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G wireless networks, there is a risk of unauthorized electronic intrusion that can maliciously control Time-Sensitive Networking (TSN) devices, potentially disrupting the synchronization of time-aware systems and networks, which can impact the coordination and communication across local and core networks.

Innovation Solution

Implementing a system where device-side translator functions (DS-TT) in 5G wireless networks are authenticated through the transparent wireless forwarding of identity and credential values, formatted as Port Management Information containers, to ensure only authorized devices can participate in the selection of the best master clock, thereby preventing malicious control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If DS-TT functions are allowed to participate in master clock selection without authentication, then network synchronization functionality is maintained, but the network becomes vulnerable to malicious intrusion and unauthorized control

Engineering Contradiction:
Improvenetwork synchronization reliabilityVSAvoidmalicious intrusion risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements authentication of DS-TT functions before allowing them to participate in master clock selection. The authentication mechanism verifies identity and credential values in advance, ensuring that only authorized devices can join the synchronization process. This preliminary security check prevents malicious intruders from compromising the network while maintaining the integrity of time-sensitive communications.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If authentication mechanisms are implemented for DS-TT functions, then network security against malicious intrusion is improved, but the complexity of the system increases

Engineering Contradiction:
Improvemalicious intrusion protectionVSAvoidauthentication system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent introduces an authentication server as an intermediary component that handles the verification of DS-TT functions. This server receives identity and credential values from attempting devices, performs authentication, and grants or denies access to master clock selection participation. By centralizing the authentication logic in a dedicated intermediary component, the system achieves robust security without distributing complex authentication code across all network devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If transparent wireless forwarding of identity and credential values is implemented, then authentication efficiency is maintained, but the risk of credential interception during transmission increases

Engineering Contradiction:
Improveauthentication processing speedVSAvoidcredential security during transmission
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent replaces physical security measures with cryptographic authentication mechanisms. Instead of relying on secure physical channels for credential transmission, the system uses encrypted digital credentials and authentication protocols that can be transmitted wirelessly. The authentication server verifies these cryptographic credentials to authenticate DS-TT functions, maintaining security through mathematical rather than physical means.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11863979B2Systems and methods for authenticating time-sensitive network elements
Publication Date: 2024.01.02 NOKIA TECHNOLOGIES OY
  • US11863979B2 patent drawing
  • US11863979B2 patent drawing
  • US11863979B2 patent drawing

AI summary

Device-side, translator functions may be authenticated by elements of a 5G core network before communications involving such functions are allowed to occur, or continue to occur.