PCRF Service Chaining Security Rules
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 3G/4G network service chains lack personalized security measures for end users, relying on generic security policies that fail to address specific user needs, such as location-based and time-dependent filtering requirements.
Innovation Solution
Implementing a Policy and Charging Rules Function (PCRF) to identify and provide customized security rules to service functions within the service chain, using enhanced Diameter messages with specific Attribute Value Pairs, enabling filtering and blocking of Service Data Flows based on user-specific criteria like location and time-of-day.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If generic security policies are applied to all Service Data Flows in the service chain, then network-wide security coverage is achieved, but personalized security requirements of end users cannot be satisfied
Solution Approach 1:
The security policy is segmented into two distinct layers: generic security policies that apply network-wide to all SDFs, and customized security rules that apply specifically to individual end users. This segmentation allows the system to maintain both broad coverage and personalized protection without creating an unmanageably complex monolithic policy structure.
Solution Approach 2:
The patent implements local quality by applying different security characteristics to different parts of the system. Generic security policies provide baseline protection uniformly across the network, while customized security rules provide location-specific and user-specific security enhancements at particular points in the service chain, ensuring that security measures are tailored to local requirements rather than applying a one-size-fits-all approach.
2Reliability
If customized security rules are implemented for each end user, then personalized security filtering is achieved, but network operation and management complexity increases
Solution Approach 1:
The system performs preliminary action by pre-configuring customized security rules in the PCRF before they are needed. When an end user requests a service, the PCRF has already prepared the appropriate security rules based on the user's profile and requirements, allowing for rapid deployment of personalized security without requiring complex real-time decision-making or manual configuration during operation.
Solution Approach 2:
The PCRF acts as an intermediary between the generic security policies and the customized security rules. It receives the generic policies, processes them against user-specific requirements, and generates the appropriate customized security rules that are then applied in the service chain. This intermediary role simplifies network operation by centralizing the complexity of rule generation and management in a single intelligent component.
3Adaptability or versatility
If service chains process all Service Data Flows with generic security policies, then network-wide security coverage is maintained, but location-based and time-dependent filtering requirements cannot be met
Solution Approach 1:
The security rules are made dynamic by incorporating time-dependent and location-dependent parameters. The PCRF generates customized security rules that can change based on the end user's current location and time of day, allowing the service chain to adapt its security behavior dynamically rather than relying on static generic policies. This enables the system to meet location-based and time-dependent filtering requirements while managing complexity through automated rule generation.
Data Source
AI summary
Embodiments described herein provide security for end users of User Equipment (UE) that utilize service chaining for Service Data Flows (SDFs). One embodiment comprises a Policy and Charging Rules Function (PCRF) that determines that a service chain is enabled for a SDF requested by an end user of a UE. The PCRF identifies a service function implemented in the service chain that processes the SDF based on a generic security policy, and identifies a security rule for the end user for filtering the SDF by the service function. The PCRF provides the security rule to the service function for filtering the SDF within the service chain.


