QoS Flow Security Policy Management in Mobile Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The evolving security requirements in mobile communications systems necessitate more flexible and optimized security protection for service data, as existing methods often rely on a single security policy for all services, failing to adapt to diverse security needs.

Innovation Solution

Implementing a communication method that uses quality of service (QoS) flows to set and manage distinct security policies for different services, allowing for dynamic security policy management between session management devices, mobility management devices, access network nodes, and terminals, ensuring consistent security policies across the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single security policy is used for all services, then the system is simple to manage, but it cannot satisfy diverse security requirements of different services

Engineering Contradiction:
Improvesecurity policy adaptabilityVSAvoidsecurity policy management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the security policy management by introducing QoS flow as a granular unit. Each QoS flow can be assigned its own security policy independently, allowing different security requirements for different services while maintaining manageable complexity through structured policy assignment at the flow level rather than service level

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by allowing different security policies to be applied to different QoS flows within the same session. This enables localized security customization where each flow receives appropriate security protection based on its specific requirements, rather than applying a uniform policy across all services

Inventive Principle:
Principle #3Local quality

2Reliability

If security policies are dynamically managed for different QoS flows, then security requirements of different services are satisfied, but the complexity of policy coordination between network elements increases

Engineering Contradiction:
Improvesecurity protection reliabilityVSAvoidpolicy coordination complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements feedback mechanisms where the SMF receives QoS flow establishment requests from the AMF, determines appropriate security policies, and sends configuration information back to both the AMF and the access network device. This feedback loop ensures consistent security policy application across all network elements while maintaining centralized control

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The SMF acts as an intermediary between the AMF and the access network device for security policy coordination. It receives QoS flow information from the AMF, determines the security policies, and distributes the appropriate configuration information to both the AMF and access network device, simplifying the coordination complexity by centralizing policy determination

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If security policies are assigned at the QoS flow level, then flexibility of network security is improved, but the overhead of policy configuration and management increases

Engineering Contradiction:
Improvesecurity policy flexibilityVSAvoidpolicy configuration overhead
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent applies universality by using the QoS flow as a multi-functional parameter that serves both QoS management and security policy assignment purposes. The same QoS flow identifier that distinguishes different service quality levels also serves as the basis for assigning appropriate security policies, reducing configuration overhead by leveraging existing QoS flow structures

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11546771B2Communication method, communications apparatus, and system
Publication Date: 2023.01.03 HUAWEI TECH CO LTD
  • US11546771B2 patent drawing
  • US11546771B2 patent drawing
  • US11546771B2 patent drawing

AI summary

A communication method includes receiving, by an access network (AN) node, indication information from a mobility management device. The indication information is indicative of a security policy of a quality of service (QoS) flow. The method also includes obtaining, by the access network node based on the indication information, security information of a radio bearer corresponding to the QoS flow. The security information is indicative of a security policy of the radio bearer. The method further includes sending, by the access network node, an identifier of the radio bearer and the security information of the radio bearer to a terminal.