Flexible Security Feature Selection in Mobile Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security negotiation mechanisms in mobile communication networks do not allow for separate selection of integrity algorithms for the control plane and user plane, limiting flexibility in providing security features according to specific use cases, such as IoT where battery life constraints may require different security configurations.

Innovation Solution

Modifying the security negotiation process to enable independent selection of integrity algorithms for the control plane and user plane, allowing for scenarios where either or both may be activated, with indicators in the 'MS network capability' element to specify algorithm applicability, and including separate indicators for confidentiality and integrity requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single integrity algorithm is selected for both control plane and user plane, then the security negotiation process is simplified, but the flexibility to accommodate different use cases (e.g., IoT devices with battery constraints) is reduced

Engineering Contradiction:
Improvesecurity negotiation processVSAvoidflexibility in security configuration
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent segments the integrity algorithm selection into two independent parts: control plane integrity algorithm and user plane integrity algorithm. This allows each plane to have its own security configuration, enabling flexible adaptation to different use cases while maintaining a structured negotiation process.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dynamic selection capability where the network can independently choose different integrity algorithms for control plane and user plane based on specific service requirements, device capabilities, and security policies. This dynamic approach enhances adaptability without significantly complicating the negotiation process.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If separate integrity algorithms are selected for control plane and user plane, then flexibility for different use cases is improved, but the security negotiation mechanism becomes more complex

Engineering Contradiction:
Improveflexibility in security configurationVSAvoidsecurity negotiation process
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent divides the security negotiation into separate stages for control plane and user plane integrity algorithm selection. This segmentation allows independent optimization of each plane's security configuration while keeping the overall negotiation process manageable through structured information elements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal security negotiation framework that can accommodate both single-algorithm and dual-algorithm scenarios. The information elements are designed to be multi-functional, supporting various configuration options (same algorithm for both planes, different algorithms, or optional integrity for either plane) within a unified structure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If integrity protection is configured for data radio bearer, then user plane security is enhanced, but battery life of energy-constrained devices may be reduced

Engineering Contradiction:
Improveuser plane securityVSAvoidbattery life
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by allowing integrity protection to be selectively enabled or disabled for user plane data radio bearers based on specific service requirements and device capabilities. Energy-constrained devices can opt-out of user plane integrity while maintaining control plane security, thereby preserving battery life where possible.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces dynamic control over user plane integrity protection, where the network can configure it based on real-time service requirements and device status. This dynamic approach allows energy-constrained devices to maintain user plane integrity only when necessary for specific services, optimizing the balance between security and energy consumption.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11588860B2Flexible selection of security features in mobile networks
Publication Date: 2023.02.21 NOKIA SOLUTIONS & NETWORKS OY
  • US11588860B2 patent drawing
  • US11588860B2 patent drawing
  • US11588860B2 patent drawing

AI summary

Various communication systems may benefit from appropriate security measures. For example, mobile networks may benefit from the flexible selection of security features. A method can include receiving an attach request. The method can also include sending a response to the request. The response can include information configured to allow selection of a control plane integrity algorithm independently of a user plane integrity algorithm.