Dynamic Security Enforcement in 5G User Plane via Policy Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G communication networks face challenges in dynamic security management, particularly in enforcing security policies across user equipment and network entities, with existing approaches being static and lacking end-to-end security enforcement, which is inadequate for scalable and flexible security requirements in diverse use cases.

Innovation Solution

Implementing a policy control framework with enhanced security analytics to dynamically enforce security policies within the user plane, considering security as a quality element of the network, and applying quality-of-service principles to security enforcement, enabling end-to-end security management across network domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static security policies are used in 5G networks, then device complexity is reduced and ease of operation is improved, but security reliability and adaptability to diverse use cases deteriorate

Engineering Contradiction:
Improvesecurity enforcementVSAvoidsecurity management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic security policies that can be adjusted in real-time based on network conditions, user behavior, and threat levels. The security management system transitions from static configuration to dynamic enforcement, allowing security parameters to change adaptively without requiring complex manual reconfiguration at each device level.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces a security management function (SMF) and policy control function (PCF) as intermediary entities between the core network and user equipment. These intermediaries centralize security decision-making, reducing the complexity burden on individual devices while maintaining high security enforcement through coordinated network-wide policy implementation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If end-to-end security enforcement is implemented across all network domains, then security reliability is improved, but device complexity and system complexity increase

Engineering Contradiction:
Improveend-to-end securityVSAvoidsecurity enforcement mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments security enforcement into distinct functional components: access and mobility management function (AMF) for access control, session management function (SMF) for session-level security, and user plane function (UPF) for data plane security. This segmentation allows each component to handle specific security tasks independently, reducing overall system complexity while achieving comprehensive end-to-end security coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal security framework where the SMF and PCF serve multiple functions across different network domains and use cases. These multi-functional entities can enforce security policies for various service types (eMBB, URLLC, massive IoT) without requiring separate dedicated security mechanisms for each, thereby reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If dynamic security policies are enforced in real-time, then adaptability to security threats is improved, but processing speed and energy consumption increase

Engineering Contradiction:
Improvesecurity policy adaptationVSAvoidnetwork entity processing
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The patent implements preliminary security assessments and pre-established security profiles for different user equipment and service types. By performing security evaluations in advance and caching security policies, the system reduces real-time processing requirements while maintaining high adaptability. The SMF and PCF can quickly enforce pre-determined security measures without extensive real-time computation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent establishes feedback loops where security enforcement outcomes and threat detection results are continuously monitored and fed back to the PCF and SMF. This feedback mechanism enables intelligent policy adjustment based on actual network conditions and threat patterns, allowing the system to adapt dynamically while optimizing resource usage by learning from historical data and reducing redundant processing.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12126658B2Security enforcement and assurance utilizing policy control framework and security enhancement of analytics function in communication network
Publication Date: 2024.10.22 NOKIA TECHNOLOGIES OY
  • US12126658B2 patent drawing
  • US12126658B2 patent drawing
  • US12126658B2 patent drawing

AI summary

Techniques for dynamic security management in a communications network are disclosed. For example, a method comprises obtaining, at a network entity in a communication network, security information from one or more other network entities in the communication network. In response to at least a portion of the obtained security information, the method enables, by the network entity, dynamic enforcement within a user plane of the communication network of one or more security policies in accordance with one or more quality-of-service policies to manage one or more behaviors of user equipment.