NF Interface Certificates for Secure Multi-Slice Communications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network slicing introduces security risks due to unauthorized use of shared resources and unauthorized connections between network functions (NFs) deployed in different slices, which can adversely affect the operation of other slices.

Innovation Solution

A method and device for dynamically creating and managing trusted domains by issuing digital certificates signed by a Certificate Authority (CA) for each NF interface, ensuring secure communications by distributing trusted CA certificates only to authorized counterparts, and updating these domains dynamically in response to network changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network slicing is implemented to enable virtualized logical networks on shared infrastructure, then network resource utilization and flexibility are improved, but security risks increase due to potential unauthorized access and communications between different network slices

Engineering Contradiction:
Improvenetwork resource utilizationVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the network into isolated slices with dedicated security boundaries. Each network slice is assigned its own security context and isolation policies, preventing unauthorized cross-slice communications while maintaining resource sharing at the physical infrastructure level.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a Network Slice Security Manager (NSSM) as an intermediary component that mediates security operations between network slices. The NSSM manages security contexts, enforces isolation policies, and coordinates authentication mechanisms to prevent unauthorized access while enabling legitimate communications.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual configuration of trusted domains and digital certificates is used for securing NF communications, then security can be maintained, but human errors increase and deployment complexity rises

Engineering Contradiction:
ImprovesecurityVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables automated self-service for security certificate management. The Network Slice Security Manager automatically discovers network functions, generates digital certificates, establishes trusted domains, and updates security contexts without manual intervention. This automation eliminates human errors while reducing deployment complexity through programmatic security establishment.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary security setup by pre-establishing trusted domains and digital certificates before network functions become operational. The system proactively configures security contexts and authentication mechanisms in advance, ensuring security is embedded from the outset rather than configured manually during deployment.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If static security configurations are used for network slices, then security policies can be enforced, but the system cannot adapt to dynamic network changes and new slice deployments

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoiddynamic adaptation
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security configurations that automatically adapt to network changes. The Network Slice Security Manager continuously monitors network topology changes, slice deployments, and NF lifecycles, updating security contexts and trusted domains in real-time. This dynamic approach maintains security policy enforcement while enabling flexible adaptation to changing network conditions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent incorporates feedback mechanisms where the security management system continuously monitors network state changes and adjusts security configurations accordingly. When new network slices are deployed or existing slices are modified, the system receives feedback about these changes and automatically updates security contexts, trusted domains, and isolation policies to maintain appropriate security enforcement.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20260100849A1Supporting secure communications between network functions
Publication Date: 2026.04.09 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20260100849A1 patent drawing
  • US20260100849A1 patent drawing
  • US20260100849A1 patent drawing

AI summary

A method for supporting secure communications between network functions (NFs) deployed in a network having two or more network slices is provided. The method is performed by a computing device and comprises: for each one of the NFs, and for each interface of the NF, if the interface does not have a valid digital certificate: obtaining based on one or more attributes and on one or more isolation requirements associated with the NF, a digital certificate signed by a certification authority (CA), and a trusted CA certificate of the CA, transmitting, to the NF, the obtained digital certificate; identifying one or more further NFs connected to the NF; and if one or more of the one or more further NFs do not have the trusted CA certificate, transmitting the trusted CA certificate to the one or more further NFs not having the trusted CA certificate.