Mobile Network Trust Indication Evaluation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G systems lack a continuous or on-demand dynamic mechanism to evaluate the trustworthiness of communication points, such as network functions, which is a key principle of zero trust security, and existing solutions only provide instantaneous information on abnormal behaviors without considering broader trustworthiness based on statistical data and risk predictions.

Innovation Solution

A system that collects information on messages exchanged between mobile networks over a time period to determine a trust indication, which includes a trust score indicating the trustworthiness of a mobile network or network function, and uses this trust indication to configure roaming operations, filter traffic, or decommission untrustworthy entities, employing analytics functions like NWDAF and SEPP to continuously monitor and update trust scores.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If instantaneous abnormal behavior detection is used, then security monitoring capability is improved, but continuous trust evaluation capability deteriorates

Engineering Contradiction:
Improveabnormal behavior detection accuracyVSAvoidtrust evaluation time span
Core Design Contradiction:
Measurement precisionVSDuration of action of stationary object

Solution Approach 1:

The system collects trust-relevant information continuously over time periods before making trust evaluations. This preliminary data collection enables the system to assess trustworthiness based on historical behavior patterns rather than reacting only to instantaneous anomalies, thus resolving the contradiction between precise anomaly detection and continuous trust evaluation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements continuous information collection about network function behaviors, messages exchanged, and security events over defined time periods. This continuous monitoring and evaluation process ensures that trust assessments are ongoing rather than momentary, addressing the limitation of instantaneous detection while maintaining security monitoring effectiveness

Inventive Principle:
Principle #20Continuity of useful action

2Measurement precision

If comprehensive trust evaluation data is collected, then trust assessment accuracy is improved, but system complexity deteriorates

Engineering Contradiction:
Improvetrust assessment accuracyVSAvoiddata collection and processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The trust evaluation system is divided into modular components: information collection modules that gather specific trust-relevant data, processing modules that analyze the collected information, and evaluation modules that generate trust indications. This segmentation allows comprehensive data collection while managing system complexity through organized, independent functional blocks

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary entities such as the Network Data Analytics Function (NWDAF) and Security Edge Protection Proxy (SEPP) that mediate between raw data sources and trust evaluation processes. These intermediaries collect, process, and standardize information from multiple sources before presenting it for trust assessment, reducing the complexity burden on the core evaluation system

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If dynamic trust indication is implemented, then security response effectiveness is improved, but implementation complexity deteriorates

Engineering Contradiction:
Improvesecurity response effectivenessVSAvoiddynamic evaluation mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements dynamic trust indications that are continuously updated based on newly collected information and changing network conditions. Trust scores and indications adjust in real-time to reflect current network function behaviors, enabling responsive security decisions while using standardized protocols to manage implementation complexity

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent establishes feedback loops where trust evaluation results are communicated back to network operators and system components. This feedback mechanism enables continuous improvement of security responses based on evaluated trust levels, with the system learning from past evaluations to refine future assessments, thereby improving effectiveness while maintaining manageable complexity through iterative optimization

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP4297459A1Method and apparatus for determining and utilizing a trust indication in mobile networks
Publication Date: 2023.12.27 NOKIA TECHNOLOGIES OY
  • EP4297459A1 patent drawingFigure 1
  • EP4297459A1 patent drawingFigure 2
  • EP4297459A1 patent drawingFigure 3

AI summary

Methods and apparatus are disclosed for. A method comprises, collecting information on messages exchanged between a first mobile network and a second mobile network during a time period; and determining a trust indication of the first mobile network at least based on the collected information. The trust indication of the first mobile network indicates a level of trustworthiness of the first mobile network.