Inter-Domain Message Protection Policy for Wireless Core Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication systems face challenges in protecting messages transmitted between different core network domains, as existing solutions require impractical administrative and operational overhead to ensure confidentiality and integrity, especially when internetwork exchange providers need to read or modify messages for service provision.

Innovation Solution

A protection policy is implemented that selectively applies or removes inter-domain security protection to specific portions of messages, allowing for dynamic updates and inclusion within the message itself, using regular expressions or JSON Pointers to identify protected portions, enabling flexible protection without requiring extensive configuration changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If inter-domain security protection is applied to the entire message, then confidentiality and integrity are ensured, but internetwork exchange providers cannot read or modify messages for service provision

Engineering Contradiction:
Improveconfidentiality and integrity protectionVSAvoidmessage accessibility for service provision
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The message is divided into multiple portions with different protection requirements. The protection policy identifies specific portions (e.g., using regular expressions or JSON Pointers) that require security protection while allowing other portions to remain accessible. This segmentation enables simultaneous protection of sensitive data and accessibility of service-relevant data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different portions of the message are assigned different security qualities. Critical portions (e.g., user identifiers, authentication data) receive full security protection, while non-critical portions (e.g., service routing information) remain unprotected for provider accessibility. This local differentiation resolves the contradiction between overall protection and selective accessibility.

Inventive Principle:
Principle #3Local quality

2Reliability

If protection is applied to the entire message, then security is maintained, but administrative and operational overhead increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidadministrative and operational overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

By segmenting the message into protected and unprotected portions, the system reduces the amount of data requiring security processing. This decreases computational overhead for encryption/decryption and reduces administrative complexity for policy management and key distribution.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The protection policy dynamically adjusts security parameters based on message content and type. Rather than applying uniform maximum protection to all messages, the system modifies protection levels according to specific message characteristics, reducing unnecessary security overhead while maintaining essential protection.

Inventive Principle:
Principle #35Parameter changes

3Ease of manufacture

If protection policy is statically configured, then implementation is straightforward, but it cannot adapt to evolving communication formats

Engineering Contradiction:
Improveimplementation simplicityVSAvoidadaptability to evolving formats
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The protection policy is designed to be dynamic rather than static. It can be updated to reflect evolving communication formats and security requirements. The policy mechanism allows for adding, removing, or modifying protection rules without requiring complete reconfiguration, enabling adaptation to new message types and formats.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The protection policy framework is designed to handle multiple message formats and types through a universal mechanism. Rather than requiring format-specific protection configurations, the system uses a unified policy approach that can accommodate evolving communication standards while maintaining implementation simplicity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250106622A1Protecting a message transmitted between core network domains
Publication Date: 2025.03.27 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20250106622A1 patent drawing
  • US20250106622A1 patent drawing
  • US20250106622A1 patent drawing

AI summary

Network equipment is configured for use in one of multiple different core network domains of a wireless communication system. The network equipment is configured to receive a message that has been, or is to be, transmitted between the different core network domains. The network equipment is also configured to apply inter-domain security protection to, or remove inter-domain security protection from, one or more portions of the content of a field in the message according to a protection policy. The protection policy includes information indicating to which one or more portions of the content inter-domain security protection is to be applied or removed. The network equipment is also configured to forward the message, with inter-domain security protection applied or removed to the one or more portions, towards a destination of the message.