Inter-Domain Message Protection Policy for Wireless Core Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication systems face challenges in protecting messages transmitted between different core network domains, as existing solutions require impractical administrative and operational overhead to ensure confidentiality and integrity, especially when internetwork exchange providers need to read or modify messages for service provision.
Innovation Solution
A protection policy is implemented that selectively applies or removes inter-domain security protection to specific portions of messages, allowing for dynamic updates and inclusion within the message itself, using regular expressions or JSON Pointers to identify protected portions, enabling flexible protection without requiring extensive configuration changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If inter-domain security protection is applied to the entire message, then confidentiality and integrity are ensured, but internetwork exchange providers cannot read or modify messages for service provision
Solution Approach 1:
The message is divided into multiple portions with different protection requirements. The protection policy identifies specific portions (e.g., using regular expressions or JSON Pointers) that require security protection while allowing other portions to remain accessible. This segmentation enables simultaneous protection of sensitive data and accessibility of service-relevant data.
Solution Approach 2:
Different portions of the message are assigned different security qualities. Critical portions (e.g., user identifiers, authentication data) receive full security protection, while non-critical portions (e.g., service routing information) remain unprotected for provider accessibility. This local differentiation resolves the contradiction between overall protection and selective accessibility.
2Reliability
If protection is applied to the entire message, then security is maintained, but administrative and operational overhead increases
Solution Approach 1:
By segmenting the message into protected and unprotected portions, the system reduces the amount of data requiring security processing. This decreases computational overhead for encryption/decryption and reduces administrative complexity for policy management and key distribution.
Solution Approach 2:
The protection policy dynamically adjusts security parameters based on message content and type. Rather than applying uniform maximum protection to all messages, the system modifies protection levels according to specific message characteristics, reducing unnecessary security overhead while maintaining essential protection.
3Ease of manufacture
If protection policy is statically configured, then implementation is straightforward, but it cannot adapt to evolving communication formats
Solution Approach 1:
The protection policy is designed to be dynamic rather than static. It can be updated to reflect evolving communication formats and security requirements. The policy mechanism allows for adding, removing, or modifying protection rules without requiring complete reconfiguration, enabling adaptation to new message types and formats.
Solution Approach 2:
The protection policy framework is designed to handle multiple message formats and types through a universal mechanism. Rather than requiring format-specific protection configurations, the system uses a unified policy approach that can accommodate evolving communication standards while maintaining implementation simplicity.
Data Source
AI summary
Network equipment is configured for use in one of multiple different core network domains of a wireless communication system. The network equipment is configured to receive a message that has been, or is to be, transmitted between the different core network domains. The network equipment is also configured to apply inter-domain security protection to, or remove inter-domain security protection from, one or more portions of the content of a field in the message according to a protection policy. The protection policy includes information indicating to which one or more portions of the content inter-domain security protection is to be applied or removed. The network equipment is also configured to forward the message, with inter-domain security protection applied or removed to the one or more portions, towards a destination of the message.


