Integrated Network Slice Encryption Service for Wireless Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security standards for wireless networks, such as those defined by 3GPP, do not account for integrated network slice encryption between user equipment, a mobile network, and third-party security entities, leaving a gap in security protection for user plane traffic and application service sessions.
Innovation Solution
An integrated network slice encryption service that provides end-to-end application layer encryption and decryption services by provisioning user plane devices with encryption/decryption algorithms and key management systems, allowing third-party devices to select and configure encryption services across wireless networks and application service layers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If current security standards (3GPP) are used for wireless networks, then basic network security is maintained, but integrated network slice encryption between user equipment, mobile network, and third-party security entities is not provided
Solution Approach 1:
The patent implements a universal security framework where the security entity can provide integrated encryption services across multiple network slices and third-party applications. The system is designed to work with existing 3GPP standards while adding multi-functional encryption capabilities that adapt to different network slices and external applications, making the security infrastructure both reliable and versatile.
Solution Approach 2:
The patent segments the security architecture into distinct functional components: the core network security functions, the security entity (SE), and third-party application interfaces. This segmentation allows each component to operate independently while maintaining integrated encryption across network slices, resolving the contradiction between maintaining basic security standards and enabling advanced integration capabilities.
2Reliability
If integrated network slice encryption is implemented, then security protection for user plane traffic and application service sessions is enhanced, but complexity of the security system increases
Solution Approach 1:
The patent introduces a security entity (SE) as an intermediary component that mediates between the core network and third-party applications. This intermediary handles the complex encryption and decryption operations, providing enhanced security protection while shielding the rest of the system from complexity. The SE acts as a buffer that manages cryptographic operations without requiring complex integration across all network components.
Solution Approach 2:
The security entity performs self-service by autonomously managing encryption keys, algorithms, and cryptographic operations. This self-service capability reduces the need for complex manual configuration and management across the network, allowing the system to maintain enhanced security protection while minimizing the operational complexity burden on network administrators and users.
3Adaptability or versatility
If third-party devices are allowed to select and provision user plane devices for encryption services, then adaptability and customization are improved, but control and management complexity increases
Solution Approach 1:
The patent implements feedback mechanisms where the security entity continuously monitors and reports on the status of encryption services, device provisioning, and security parameters. This feedback loop enables third-party devices to select and provision user plane devices with appropriate encryption services while maintaining centralized visibility and control. The feedback system provides real-time information about service status, allowing operators to manage complexity through automated monitoring rather than manual intervention.
Data Source
AI summary
A method, a network device, and a non-transitory computer-readable storage medium are described in relation to an integrated network slice encryption service. The integrated network slice encryption service may manage and provision encryption and/or decryption services associated with a third party and relative to a network slice and end device application associated with a service provider and application provider. The integrated network slice encryption service may provision end devices, core network devices, and application layer devices of an external network.


