PCRF Node Dynamic Control Rule Provisioning for Network Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Policy and Charging Control (PCC) architectures in communication networks face challenges in dynamically provisioning control rules and detecting services, especially with encrypted traffic and static service configurations, which can lead to inefficient service delivery and increased complexity.

Innovation Solution

The method involves an identity management node authenticating user equipment (UE) and sending authentication information to a Policy and Charging Rules Function (PCRF) node, which determines and installs control rules in network nodes to enforce specific packet-forwarding treatments, such as accelerated content delivery and charging types, based on the authentication level and service requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If static service configurations are used in PCC architectures, then network simplicity is maintained, but service delivery efficiency deteriorates due to inability to dynamically adapt to authentication levels and traffic types

Engineering Contradiction:
Improveservice delivery efficiencyVSAvoidnetwork configuration complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements dynamic service configurations that adapt based on authentication levels and traffic detection results. The PCRF node receives authentication information from the identity management node and dynamically determines control rules, allowing the network to transition from static to dynamic configuration. This enables efficient service delivery for different user types (e.g., corporate employees vs. general users) without requiring manual reconfiguration of network elements.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary authentication and service configuration before actual service delivery. The identity management node authenticates the UE and sends authentication information to the PCRF node in advance, which then determines and installs control rules before traffic flows are established. This preliminary action ensures that appropriate service treatments are already in place when services begin, improving delivery efficiency without adding complexity during active service operations.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If control rules are manually configured in network elements, then implementation complexity is reduced, but adaptability to different services and authentication levels deteriorates

Engineering Contradiction:
Improveservice adaptation capabilityVSAvoidcontrol rule provisioning complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements self-service provisioning where the PCRF node automatically determines and installs control rules based on authentication information received from the identity management node. The network elements (PCEF, TDF, BBERF) automatically receive and enforce control rules without manual configuration. This self-service mechanism provides high adaptability to different services and authentication levels while keeping implementation complexity low, as the system self-configures based on incoming authentication data.

Inventive Principle:
Principle #25Self-service

3Reliability

If authentication information is not integrated with policy control, then system simplicity is maintained, but service quality deteriorates due to inability to provide differentiated treatments

Engineering Contradiction:
Improveservice qualityVSAvoidarchitecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges authentication information integration with policy control by establishing a direct interface between the identity management node and the PCRF node. The authentication information (including authentication level and type) is combined with service information and sent to the PCRF node, which then determines control rules that reflect both authentication status and service requirements. This merging enables differentiated service treatments (e.g., accelerated content delivery for authenticated users, specific charging types) while maintaining architectural simplicity through standardized interface definitions.

Inventive Principle:
Principle #5Merging (Combining)

4Adaptability or versatility

If dynamic control rule provisioning is implemented, then service flexibility is improved, but implementation and architecture complexity increases

Engineering Contradiction:
Improveservice flexibilityVSAvoidarchitecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The PCRF node serves as an intermediary that simplifies dynamic control rule provisioning. It receives authentication information from the identity management node, determines appropriate control rules, and installs them in the relevant network elements (PCEF, TDF, BBERF). This intermediary approach provides service flexibility through automatic rule determination while reducing implementation complexity by centralizing the rule provisioning logic in a single dedicated node, avoiding the need for complex distributed configuration management across multiple network elements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10681086B2Methods, devices and computer programs for subjecting traffic associated with a service to a specific treatment
Publication Date: 2020.06.09 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US10681086B2 patent drawing
  • US10681086B2 patent drawing
  • US10681086B2 patent drawing

AI summary

A method aims at providing a service in a communication network, and comprises the following steps. An access to a service requiring authentication is initiated by a UE (100), An identity management node (300) authenticates the UE, and then sends, to a PCRF node (400), a message comprising: service information for identifying the service to which access is initiated, identification information for identifying the UE, and authentication information determined upon authenticating the UE. The PCRF node determines control rules to be applied to the service for the UE, based on the authentication information and service information. The PCRF node then triggers installation of the control rules in at least one network node (500) handling service data flows (SDF) for the service, to enforce the control rules on traffic associated with the service for the UE. The invention also relates to devices and computer programs for carrying such as method.