Network Initiated PDP Context Encryption for Selective IP Session Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security methods for IP sessions are rigid and inflexible, requiring all traffic to and from mobile terminals to be encrypted once initiated, which does not allow for selective encryption of specific IP sessions and lacks dynamic adaptability to changing security requirements.

Innovation Solution

A network system that uses packet data protocol (PDP) context to initiate and modify network security for specific IP sessions by generating and forwarding activation or modification request messages containing security information elements from a gateway general packet radio service support node (GGSN) to a serving general packet radio service support node (SGSN), allowing for selective encryption of IP sessions based on security information elements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional encryption method is activated, then network security is provided, but all IP traffic to and from mobile terminal is encrypted which is rigid and inflexible

Engineering Contradiction:
Improvenetwork securityVSAvoidflexibility of encryption
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the encryption scope from all IP traffic to specific IP sessions. By identifying individual IP sessions and applying encryption selectively to each session based on security requirements, the system achieves both network security and operational flexibility. The segmentation allows different encryption policies to be applied to different sessions simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic encryption activation where encryption is not statically applied to all traffic but is dynamically initiated for specific IP sessions based on real-time security requirements. The system can activate or deactivate encryption for individual sessions as needed, providing adaptability while maintaining security where required.

Inventive Principle:
Principle #15Dynamics

2Reliability

If conventional encryption method is used, then data traffic is encrypted, but mobile user needs to be informed that encryption is required which reduces ease of operation

Engineering Contradiction:
Improvedata encryptionVSAvoiduser notification requirement
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables the network system to automatically initiate and manage encryption for IP sessions without requiring user awareness or action. The system autonomously identifies sessions requiring encryption, activates the appropriate security parameters, and manages the encryption process, thereby maintaining ease of operation while ensuring data security.

Inventive Principle:
Principle #25Self-service

3Reliability

If all IP traffic is encrypted, then security is maintained, but encryption overhead increases which reduces productivity

Engineering Contradiction:
Improvesecurity maintenanceVSAvoidencryption overhead
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial encryption action by encrypting only specific IP sessions that require security rather than all IP traffic. This selective approach reduces the overall encryption overhead and processing burden on the network while maintaining security for sessions where it is necessary, thereby improving productivity without compromising security where needed.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8862869B1Method and apparatus for providing network initiated session encryption
Publication Date: 2014.10.14 TELLABS OPERATIONS
  • US8862869B1 patent drawing
  • US8862869B1 patent drawing
  • US8862869B1 patent drawing

AI summary

A network system and method capable of implementing network initiated packet data protocol (“PDP”) context to enhance security of network communications are disclosed. An activation and/or modification request message containing security information element is generated and forwarded from a gateway general packet radio service support node (“GGSN”) to a serving general packet radio service support node (“SGSN”) requesting traffic security for a particular Internet Protocol (“IP”) session. After sending the activation/modification request message from SGSN to user equipment (“UE”), an IP session with PDP context encryption between the UE and a destination is initiated according to the security information element.