NF Interface Certificates for Secure Multi-Slice Communications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network slicing introduces security risks due to unauthorized use of shared resources and unauthorized connections between network functions (NFs) deployed in different slices, which can adversely affect the operation of other slices.
Innovation Solution
A method and device for dynamically creating and managing trusted domains by issuing digital certificates signed by a Certificate Authority (CA) for each NF interface, ensuring secure communications by distributing trusted CA certificates only to authorized counterparts, and updating these domains dynamically in response to network changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network slicing is implemented to enable virtualized logical networks on shared infrastructure, then network resource utilization and flexibility are improved, but security risks increase due to potential unauthorized access and communications between different network slices
Solution Approach 1:
The patent segments the network into isolated slices with dedicated security boundaries. Each network slice is assigned its own security context and isolation policies, preventing unauthorized cross-slice communications while maintaining resource sharing at the physical infrastructure level.
Solution Approach 2:
The patent introduces a Network Slice Security Manager (NSSM) as an intermediary component that mediates security operations between network slices. The NSSM manages security contexts, enforces isolation policies, and coordinates authentication mechanisms to prevent unauthorized access while enabling legitimate communications.
2Reliability
If manual configuration of trusted domains and digital certificates is used for securing NF communications, then security can be maintained, but human errors increase and deployment complexity rises
Solution Approach 1:
The patent enables automated self-service for security certificate management. The Network Slice Security Manager automatically discovers network functions, generates digital certificates, establishes trusted domains, and updates security contexts without manual intervention. This automation eliminates human errors while reducing deployment complexity through programmatic security establishment.
Solution Approach 2:
The patent performs preliminary security setup by pre-establishing trusted domains and digital certificates before network functions become operational. The system proactively configures security contexts and authentication mechanisms in advance, ensuring security is embedded from the outset rather than configured manually during deployment.
3Reliability
If static security configurations are used for network slices, then security policies can be enforced, but the system cannot adapt to dynamic network changes and new slice deployments
Solution Approach 1:
The patent implements dynamic security configurations that automatically adapt to network changes. The Network Slice Security Manager continuously monitors network topology changes, slice deployments, and NF lifecycles, updating security contexts and trusted domains in real-time. This dynamic approach maintains security policy enforcement while enabling flexible adaptation to changing network conditions.
Solution Approach 2:
The patent incorporates feedback mechanisms where the security management system continuously monitors network state changes and adjusts security configurations accordingly. When new network slices are deployed or existing slices are modified, the system receives feedback about these changes and automatically updates security contexts, trusted domains, and isolation policies to maintain appropriate security enforcement.
Data Source
AI summary
A method for supporting secure communications between network functions (NFs) deployed in a network having two or more network slices is provided. The method is performed by a computing device and comprises: for each one of the NFs, and for each interface of the NF, if the interface does not have a valid digital certificate: obtaining based on one or more attributes and on one or more isolation requirements associated with the NF, a digital certificate signed by a certification authority (CA), and a trusted CA certificate of the CA, transmitting, to the NF, the obtained digital certificate; identifying one or more further NFs connected to the NF; and if one or more of the one or more further NFs do not have the trusted CA certificate, transmitting the trusted CA certificate to the one or more further NFs not having the trusted CA certificate.


