PCRF Node Dynamic Control Rule Provisioning for Network Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Policy and Charging Control (PCC) architectures in communication networks face challenges in dynamically provisioning control rules and detecting services, especially with encrypted traffic and static service configurations, which can lead to inefficient service delivery and increased complexity.
Innovation Solution
The method involves an identity management node authenticating user equipment (UE) and sending authentication information to a Policy and Charging Rules Function (PCRF) node, which determines and installs control rules in network nodes to enforce specific packet-forwarding treatments, such as accelerated content delivery and charging types, based on the authentication level and service requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If static service configurations are used in PCC architectures, then network simplicity is maintained, but service delivery efficiency deteriorates due to inability to dynamically adapt to authentication levels and traffic types
Solution Approach 1:
The patent implements dynamic service configurations that adapt based on authentication levels and traffic detection results. The PCRF node receives authentication information from the identity management node and dynamically determines control rules, allowing the network to transition from static to dynamic configuration. This enables efficient service delivery for different user types (e.g., corporate employees vs. general users) without requiring manual reconfiguration of network elements.
Solution Approach 2:
The system performs preliminary authentication and service configuration before actual service delivery. The identity management node authenticates the UE and sends authentication information to the PCRF node in advance, which then determines and installs control rules before traffic flows are established. This preliminary action ensures that appropriate service treatments are already in place when services begin, improving delivery efficiency without adding complexity during active service operations.
2Adaptability or versatility
If control rules are manually configured in network elements, then implementation complexity is reduced, but adaptability to different services and authentication levels deteriorates
Solution Approach 1:
The system implements self-service provisioning where the PCRF node automatically determines and installs control rules based on authentication information received from the identity management node. The network elements (PCEF, TDF, BBERF) automatically receive and enforce control rules without manual configuration. This self-service mechanism provides high adaptability to different services and authentication levels while keeping implementation complexity low, as the system self-configures based on incoming authentication data.
3Reliability
If authentication information is not integrated with policy control, then system simplicity is maintained, but service quality deteriorates due to inability to provide differentiated treatments
Solution Approach 1:
The patent merges authentication information integration with policy control by establishing a direct interface between the identity management node and the PCRF node. The authentication information (including authentication level and type) is combined with service information and sent to the PCRF node, which then determines control rules that reflect both authentication status and service requirements. This merging enables differentiated service treatments (e.g., accelerated content delivery for authenticated users, specific charging types) while maintaining architectural simplicity through standardized interface definitions.
4Adaptability or versatility
If dynamic control rule provisioning is implemented, then service flexibility is improved, but implementation and architecture complexity increases
Solution Approach 1:
The PCRF node serves as an intermediary that simplifies dynamic control rule provisioning. It receives authentication information from the identity management node, determines appropriate control rules, and installs them in the relevant network elements (PCEF, TDF, BBERF). This intermediary approach provides service flexibility through automatic rule determination while reducing implementation complexity by centralizing the rule provisioning logic in a single dedicated node, avoiding the need for complex distributed configuration management across multiple network elements.
Data Source
AI summary
A method aims at providing a service in a communication network, and comprises the following steps. An access to a service requiring authentication is initiated by a UE (100), An identity management node (300) authenticates the UE, and then sends, to a PCRF node (400), a message comprising: service information for identifying the service to which access is initiated, identification information for identifying the UE, and authentication information determined upon authenticating the UE. The PCRF node determines control rules to be applied to the service for the UE, based on the authentication information and service information. The PCRF node then triggers installation of the control rules in at least one network node (500) handling service data flows (SDF) for the service, to enforce the control rules on traffic associated with the service for the UE. The invention also relates to devices and computer programs for carrying such as method.


