Enforcing Route Selection Policy Rules in Wireless Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wireless communication networks face challenges in enforcing route selection policy rules, as wireless communication devices may fail to implement these rules due to malicious activity or rule mismatches, leading to unauthorized traffic routing.
Innovation Solution
An apparatus and method within a wireless communication network are introduced to enforce route selection policy rules by identifying wireless communication devices that route unauthorized traffic. This involves receiving requests from network functions, determining third network functions with which user equipment has established connections, and reporting traffic that does not comply with the policy rules.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If the network relies on UE-provided information to determine URSP rule enforcement, then the signaling overhead is reduced, but the reliability of the enforcement detection deteriorates due to potential malicious activity or inaccuracies
Solution Approach 1:
The patent introduces an intermediary approach where the network provides a list of allowed traffic to the UE, and the UE reports only when traffic matches or does not match the allowed list. This intermediary reporting mechanism reduces signaling overhead compared to continuous reporting, while maintaining reliability through the structured match/no-match framework that prevents malicious manipulation.
Solution Approach 2:
The patent implements a feedback mechanism where the UE continuously monitors its traffic against the allowed traffic list and provides feedback reports to the network when traffic does not match. This feedback loop ensures reliable detection of enforcement violations while minimizing signaling by only reporting when necessary (i.e., when violations occur).
2Reliability
If the network implements comprehensive monitoring of all UE traffic to ensure policy compliance, then the reliability of policy enforcement is improved, but the device complexity and processing requirements increase
Solution Approach 1:
The patent applies partial action by having the UE monitor all traffic but report only when specific conditions are met (traffic match or no-match). This selective reporting approach maintains reliable policy enforcement detection while reducing the complexity of the monitoring system, as the UE does not need to process and report every single traffic flow continuously.
Solution Approach 2:
The patent extracts only the essential information needed for policy enforcement verification - specifically whether traffic matches or does not match the allowed traffic list. By extracting and reporting only this critical binary information rather than complete traffic details, the system achieves reliable enforcement monitoring with reduced device complexity and processing requirements.
3Measurement precision
If the network uses detailed traffic analysis to identify unauthorized routing, then the measurement precision of policy violation detection is improved, but the loss of time for processing and reporting increases
Solution Approach 1:
The patent extracts only the essential compliance information (match/no-match status) from detailed traffic analysis. By focusing on extracting this single binary indicator rather than analyzing and reporting complete traffic details, the system achieves precise policy violation detection while minimizing processing time and reporting overhead.
Solution Approach 2:
The patent performs preliminary action by having the UE continuously maintain an internal state of whether its current traffic matches or does not match the allowed traffic list. This preliminary monitoring and state maintenance enables rapid detection and immediate reporting of violations without requiring time-consuming analysis at the moment of violation detection.
Data Source
AI summary
A request is received from a first function, identifying a list of allowed traffic to a user plane connection, the request indicating to identify a device that routes traffic via the user plane connection that is not included in the list of allowed traffic. A request to a second function to be notified when the device establishes a user plane connection to network resources defined in a route selection policy rule. A third function is determined with which the device has established a user plane connection. A request is sent to the third function to report, for the device, traffic sent via the user plane connection that is not included in the list of allowed traffic. A report is received from the third function indicating, for the device, the traffic sent via the user plane connection that is not included in the list of allowed traffic.


