Optional Security Features in 5G Service Requests

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing techniques for handling service requests in networks often require unnecessary security features, leading to resource wastage and inefficiency, as client credentials assertions are always included, even when not required, which can be costly and inefficient.

Innovation Solution

A method where service requests and responses in networks include security features only when specifically required, with the first security feature being optional in requests and the second security feature being optional in responses, allowing for dynamic and efficient use of security protocols based on profile information and configuration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security features (client credentials assertions) are always included in service requests and responses, then security levels are maintained, but resource wastage and inefficiency occur

Engineering Contradiction:
Improvesecurity levelVSAvoidresource wastage
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies local quality by making security features optional rather than universal. Service requests and responses include security features only when specifically required by the service producer or consumer, rather than always including them. This allows different parts of the communication to have different security characteristics based on their specific needs, resolving the contradiction between maintaining security and avoiding resource wastage.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements dynamics by enabling dynamic inclusion or exclusion of security features based on real-time requirements. The service consumer or service communication proxy can dynamically determine whether to include client credentials assertions in service requests, and the service producer can dynamically determine whether to include security features in responses. This dynamic approach allows the system to adapt security levels to actual needs, preventing unnecessary resource consumption while maintaining required security.

Inventive Principle:
Principle #15Dynamics

2Reliability

If security features are always included in service requests, then authentication is ensured, but network efficiency and productivity decrease

Engineering Contradiction:
ImproveauthenticationVSAvoidnetwork efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by making security features optional rather than universal. Service requests and responses include security features only when specifically required by the service producer or consumer, rather than always including them. This allows different parts of the communication to have different security characteristics based on their specific needs, resolving the contradiction between maintaining security and avoiding resource wastage.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements dynamics by enabling dynamic inclusion or exclusion of security features based on real-time requirements. The service consumer or service communication proxy can dynamically determine whether to include client credentials assertions in service requests, and the service producer can dynamically determine whether to include security features in responses. This dynamic approach allows the system to adapt security levels to actual needs, preventing unnecessary resource consumption while maintaining required security.

Inventive Principle:
Principle #15Dynamics

3Reliability

If client credentials assertions are always included in service requests, then security is maintained, but device complexity and operational cost increase

Engineering Contradiction:
ImprovesecurityVSAvoidoperational cost
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by making security features optional rather than universal. Service requests and responses include security features only when specifically required by the service producer or consumer, rather than always including them. This allows different parts of the communication to have different security characteristics based on their specific needs, resolving the contradiction between maintaining security and avoiding resource wastage.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements dynamics by enabling dynamic inclusion or exclusion of security features based on real-time requirements. The service consumer or service communication proxy can dynamically determine whether to include client credentials assertions in service requests, and the service producer can dynamically determine whether to include security features in responses. This dynamic approach allows the system to adapt security levels to actual needs, preventing unnecessary resource consumption while maintaining required security.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20230396655A1Efficient authentication information exchange between nodes in a 5g compliant network
Publication Date: 2023.12.07 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20230396655A1 patent drawing
  • US20230396655A1 patent drawing
  • US20230396655A1 patent drawing

AI summary

There is provided a method for handling a service request. The method is performed by a first network node. The first network node is a first network function (NF) node of a service consumer or a first service communication proxy (SCP) node that is configured to operate as an SCP between the first NF node and one or more second NF nodes of a service producer. Transmission of a first request is initiated and/or a response to the first request is received (102). The first request is for a second NF node of the one or more second NF nodes to provide a first service requested by the first NF node. The first request has a first security feature only if such a first security feature is required. The response to the first request has a second security feature only if such a second security feature is required.