QoS Flow Security Configuration for Resource-Efficient PDU Sessions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication standards, such as those defined by 3GPP, lack the flexibility to adapt security configurations for different Quality of Service (QoS) flows within a Packet Data Unit (PDU) session, leading to unnecessary resource usage and inefficiency due to uniform security settings across all flows.
Innovation Solution
Implementing a system that allows for differentiated security configurations for individual QoS flows within a PDU session by using an Application Function (AF) to provide flow descriptions and User Plane Security Indications, enabling the Policy Control Function (PCF) to generate PCC rules and map traffic to specific Data Radio Bearers with tailored integrity and confidentiality protections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If uniform security configuration is applied to all QoS flows in a PDU session, then security management is simplified, but resource efficiency deteriorates due to unnecessary processing for flows that don't require such security
Solution Approach 1:
The patent segments the PDU session into multiple QoS flows, each with independent security configurations. The network can now apply different security settings (integrity protection, confidentiality protection) to different flows based on their specific requirements, rather than applying a uniform configuration to all traffic. This segmentation enables selective security processing, reducing wasted resources on flows that don't require certain security measures.
Solution Approach 2:
The patent implements local quality by allowing each QoS flow to have customized security attributes tailored to its specific requirements. For example, sensitive traffic flows can receive full integrity and confidentiality protection, while less sensitive flows can use reduced security configurations. This localized security quality optimization reduces overall processing overhead while maintaining necessary security levels for each flow type.
2Loss of energy
If differentiated security configurations are implemented for different QoS flows, then resource efficiency improves, but system complexity increases
Solution Approach 1:
The patent introduces dynamic security configuration management where the network can adjust security settings for different QoS flows based on real-time requirements. The system dynamically selects appropriate security configurations from available options, allowing flexible adaptation without requiring complex static configuration management. This dynamic approach simplifies the overall system by using standardized mechanisms applied flexibly rather than requiring custom complex configuration systems.
Solution Approach 2:
The patent changes security parameters (integrity protection level, confidentiality protection level) on a per-QoS-flow basis rather than using fixed uniform configurations. By parameterizing security settings and allowing independent adjustment for each flow, the system achieves differentiated security without proportionally increasing complexity. The same security mechanisms are used with varying parameter values, which is simpler than implementing entirely different security systems for different flows.
3Reliability
If security is applied to all QoS flows, then security coverage is maximized, but productivity decreases due to unnecessary processing overhead
Solution Approach 1:
The patent applies partial security action by selectively enabling security measures only for QoS flows that require them. Instead of applying full security coverage to all flows (excessive action), the system identifies which flows need integrity protection and confidentiality protection based on their characteristics, and applies security measures only to those flows. This partial application maintains adequate security coverage while eliminating unnecessary processing overhead that degrades network performance.
Data Source
AI summary
This disclosure describes systems, methods, and devices for quality of service (QOS)-level security configuration in a packet data unit (PDU) session. A device may identify a first user plane security indication received from an application function of a wireless network; identify a second user plane security indication received from the application function; generate, based on the first user plane security indication, a first security configuration for a first QoS flow of a PDU session; generate, based on the second user plane security indication, a second security configuration for a second QoS flow of the PDU session, the first security configuration different than the second security configuration; decode a first packet received, from the UE, in the first QoS flow using the first security configuration; and decode a second packet received, from the UE, in the second QoS flow using the second security configuration.


