Network Security Management System for 5G Authentication Module Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G networks, the lack of consideration for authentication protocols and algorithms during user equipment (UE) authentication leads to inadequate cyber security, as existing slice architecture designs do not account for these factors, resulting in low authentication module selection accuracy and efficiency.

Innovation Solution

A cyber security management system that selects an authentication module based on the authentication protocol supported by the UE, enabling mutual authentication and generating a security configuration to enhance authentication module selection accuracy and cyber security, thereby meeting differentiated authentication protocol and security policy requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication module selection is performed without considering authentication protocol information, then the selection process is simple, but authentication module selection accuracy and cyber security deteriorate

Engineering Contradiction:
Improvecyber securityVSAvoidauthentication module selection process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by obtaining authentication protocol information from the UE before performing authentication module selection. The network function selection module receives the service request, extracts authentication protocol information, and uses this information to select an appropriate authentication module. This preliminary gathering of protocol information ensures that the selected authentication module is compatible with the UE's supported protocols, thereby improving authentication module selection accuracy and cyber security without significantly complicating the overall process.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If multiple authentication modules are supported with different authentication protocols, then adaptability to different UEs is improved, but authentication module selection complexity increases

Engineering Contradiction:
Improveauthentication protocol compatibilityVSAvoidauthentication module selection process
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by using authentication protocol information as a key parameter for selecting the authentication module. The network function selection module changes the selection criterion from generic service request handling to specific authentication protocol matching. This allows the system to support multiple authentication modules with different protocols while maintaining a relatively simple selection process by directly matching the UE's supported protocols with the authentication modules' capabilities.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If authentication protocol information is obtained and considered in module selection, then authentication module selection accuracy is improved, but processing time increases

Engineering Contradiction:
Improveauthentication module selection accuracyVSAvoidauthentication processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary action by obtaining authentication protocol information at the beginning of the service request processing, before the authentication module selection is performed. This allows the network function selection module to have the protocol information readily available when making the selection, improving accuracy without requiring additional processing time during the selection phase. The protocol information is extracted and prepared in advance, ensuring that the matching process is efficient and accurate.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3468137B1Network security management system, method and device
Publication Date: 2023.05.10 HUAWEI TECH CO LTD
  • EP3468137B1 patent drawingFigure 1
  • EP3468137B1 patent drawingFigure 2
  • EP3468137B1 patent drawingFigure 3

AI summary

Embodiments of the present invention disclose a cyber security management system, method, and apparatus. The system includes UE, an AN, a network function selection module, and at least two authentication modules. The UE is configured to send a first service request to the network function selection module, where the first service request carries authentication protocol information. The network function selection module is configured to: select a target authentication module based on the authentication protocol information, and send a second service request to the target authentication module. The target authentication module is configured to perform mutual authentication with the UE. The target authentication module is further configured to: determine a first security configuration according to a specified security policy, and send the first security configuration to the AN. The AN is configured to: determine a second security configuration based on the first security configuration or the specified security policy, and send the second security configuration to the UE. According to technical solutions provided in the present invention, differential authentication protocol and security policy security requirements of a network can be met, thereby improving cyber security.