QoS Flow Security Policy Management in Mobile Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The evolving security requirements in mobile communications systems necessitate more flexible and optimized security protection for service data, as existing methods often rely on a single security policy for all services, failing to adapt to diverse security needs.
Innovation Solution
Implementing a communication method that uses quality of service (QoS) flows to set and manage distinct security policies for different services, allowing for dynamic security policy management between session management devices, mobility management devices, access network nodes, and terminals, ensuring consistent security policies across the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a single security policy is used for all services, then the system is simple to manage, but it cannot satisfy diverse security requirements of different services
Solution Approach 1:
The patent segments the security policy management by introducing QoS flow as a granular unit. Each QoS flow can be assigned its own security policy independently, allowing different security requirements for different services while maintaining manageable complexity through structured policy assignment at the flow level rather than service level
Solution Approach 2:
The patent applies local quality by allowing different security policies to be applied to different QoS flows within the same session. This enables localized security customization where each flow receives appropriate security protection based on its specific requirements, rather than applying a uniform policy across all services
2Reliability
If security policies are dynamically managed for different QoS flows, then security requirements of different services are satisfied, but the complexity of policy coordination between network elements increases
Solution Approach 1:
The patent implements feedback mechanisms where the SMF receives QoS flow establishment requests from the AMF, determines appropriate security policies, and sends configuration information back to both the AMF and the access network device. This feedback loop ensures consistent security policy application across all network elements while maintaining centralized control
Solution Approach 2:
The SMF acts as an intermediary between the AMF and the access network device for security policy coordination. It receives QoS flow information from the AMF, determines the security policies, and distributes the appropriate configuration information to both the AMF and access network device, simplifying the coordination complexity by centralizing policy determination
3Adaptability or versatility
If security policies are assigned at the QoS flow level, then flexibility of network security is improved, but the overhead of policy configuration and management increases
Solution Approach 1:
The patent applies universality by using the QoS flow as a multi-functional parameter that serves both QoS management and security policy assignment purposes. The same QoS flow identifier that distinguishes different service quality levels also serves as the basis for assigning appropriate security policies, reducing configuration overhead by leveraging existing QoS flow structures
Data Source
AI summary
A communication method includes receiving, by an access network (AN) node, indication information from a mobility management device. The indication information is indicative of a security policy of a quality of service (QoS) flow. The method also includes obtaining, by the access network node based on the indication information, security information of a radio bearer corresponding to the QoS flow. The security information is indicative of a security policy of the radio bearer. The method further includes sending, by the access network node, an identifier of the radio bearer and the security information of the radio bearer to a terminal.


