QoS Flow Security Configuration for Resource-Efficient PDU Sessions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication standards, such as those defined by 3GPP, lack the flexibility to adapt security configurations for different Quality of Service (QoS) flows within a Packet Data Unit (PDU) session, leading to unnecessary resource usage and inefficiency due to uniform security settings across all flows.

Innovation Solution

Implementing a system that allows for differentiated security configurations for individual QoS flows within a PDU session by using an Application Function (AF) to provide flow descriptions and User Plane Security Indications, enabling the Policy Control Function (PCF) to generate PCC rules and map traffic to specific Data Radio Bearers with tailored integrity and confidentiality protections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If uniform security configuration is applied to all QoS flows in a PDU session, then security management is simplified, but resource efficiency deteriorates due to unnecessary processing for flows that don't require such security

Engineering Contradiction:
Improvesecurity configuration managementVSAvoidprocessing resources
Core Design Contradiction:
Device complexityVSLoss of energy

Solution Approach 1:

The patent segments the PDU session into multiple QoS flows, each with independent security configurations. The network can now apply different security settings (integrity protection, confidentiality protection) to different flows based on their specific requirements, rather than applying a uniform configuration to all traffic. This segmentation enables selective security processing, reducing wasted resources on flows that don't require certain security measures.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by allowing each QoS flow to have customized security attributes tailored to its specific requirements. For example, sensitive traffic flows can receive full integrity and confidentiality protection, while less sensitive flows can use reduced security configurations. This localized security quality optimization reduces overall processing overhead while maintaining necessary security levels for each flow type.

Inventive Principle:
Principle #3Local quality

2Loss of energy

If differentiated security configurations are implemented for different QoS flows, then resource efficiency improves, but system complexity increases

Engineering Contradiction:
Improveprocessing resourcesVSAvoidsecurity configuration management
Core Design Contradiction:
Loss of energyVSDevice complexity

Solution Approach 1:

The patent introduces dynamic security configuration management where the network can adjust security settings for different QoS flows based on real-time requirements. The system dynamically selects appropriate security configurations from available options, allowing flexible adaptation without requiring complex static configuration management. This dynamic approach simplifies the overall system by using standardized mechanisms applied flexibly rather than requiring custom complex configuration systems.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes security parameters (integrity protection level, confidentiality protection level) on a per-QoS-flow basis rather than using fixed uniform configurations. By parameterizing security settings and allowing independent adjustment for each flow, the system achieves differentiated security without proportionally increasing complexity. The same security mechanisms are used with varying parameter values, which is simpler than implementing entirely different security systems for different flows.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If security is applied to all QoS flows, then security coverage is maximized, but productivity decreases due to unnecessary processing overhead

Engineering Contradiction:
Improvesecurity coverageVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial security action by selectively enabling security measures only for QoS flows that require them. Instead of applying full security coverage to all flows (excessive action), the system identifies which flows need integrity protection and confidentiality protection based on their characteristics, and applies security measures only to those flows. This partial application maintains adequate security coverage while eliminating unnecessary processing overhead that degrades network performance.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20260012794A1Enhanced quality of service-level security for wireless communications
Publication Date: 2026.01.08 INTEL CORP
  • US20260012794A1 patent drawing
  • US20260012794A1 patent drawing
  • US20260012794A1 patent drawing

AI summary

This disclosure describes systems, methods, and devices for quality of service (QOS)-level security configuration in a packet data unit (PDU) session. A device may identify a first user plane security indication received from an application function of a wireless network; identify a second user plane security indication received from the application function; generate, based on the first user plane security indication, a first security configuration for a first QoS flow of a PDU session; generate, based on the second user plane security indication, a second security configuration for a second QoS flow of the PDU session, the first security configuration different than the second security configuration; decode a first packet received, from the UE, in the first QoS flow using the first security configuration; and decode a second packet received, from the UE, in the second QoS flow using the second security configuration.