Flexible Security Feature Selection in Mobile Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security negotiation mechanisms in mobile communication networks do not allow for separate selection of integrity algorithms for the control plane and user plane, limiting flexibility in providing security features according to specific use cases, such as IoT where battery life constraints may require different security configurations.
Innovation Solution
Modifying the security negotiation process to enable independent selection of integrity algorithms for the control plane and user plane, allowing for scenarios where either or both may be activated, with indicators in the 'MS network capability' element to specify algorithm applicability, and including separate indicators for confidentiality and integrity requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a single integrity algorithm is selected for both control plane and user plane, then the security negotiation process is simplified, but the flexibility to accommodate different use cases (e.g., IoT devices with battery constraints) is reduced
Solution Approach 1:
The patent segments the integrity algorithm selection into two independent parts: control plane integrity algorithm and user plane integrity algorithm. This allows each plane to have its own security configuration, enabling flexible adaptation to different use cases while maintaining a structured negotiation process.
Solution Approach 2:
The patent introduces dynamic selection capability where the network can independently choose different integrity algorithms for control plane and user plane based on specific service requirements, device capabilities, and security policies. This dynamic approach enhances adaptability without significantly complicating the negotiation process.
2Adaptability or versatility
If separate integrity algorithms are selected for control plane and user plane, then flexibility for different use cases is improved, but the security negotiation mechanism becomes more complex
Solution Approach 1:
The patent divides the security negotiation into separate stages for control plane and user plane integrity algorithm selection. This segmentation allows independent optimization of each plane's security configuration while keeping the overall negotiation process manageable through structured information elements.
Solution Approach 2:
The patent creates a universal security negotiation framework that can accommodate both single-algorithm and dual-algorithm scenarios. The information elements are designed to be multi-functional, supporting various configuration options (same algorithm for both planes, different algorithms, or optional integrity for either plane) within a unified structure.
3Reliability
If integrity protection is configured for data radio bearer, then user plane security is enhanced, but battery life of energy-constrained devices may be reduced
Solution Approach 1:
The patent applies local quality by allowing integrity protection to be selectively enabled or disabled for user plane data radio bearers based on specific service requirements and device capabilities. Energy-constrained devices can opt-out of user plane integrity while maintaining control plane security, thereby preserving battery life where possible.
Solution Approach 2:
The patent introduces dynamic control over user plane integrity protection, where the network can configure it based on real-time service requirements and device status. This dynamic approach allows energy-constrained devices to maintain user plane integrity only when necessary for specific services, optimizing the balance between security and energy consumption.
Data Source
AI summary
Various communication systems may benefit from appropriate security measures. For example, mobile networks may benefit from the flexible selection of security features. A method can include receiving an attach request. The method can also include sending a response to the request. The response can include information configured to allow selection of a control plane integrity algorithm independently of a user plane integrity algorithm.


