Restricted Local Operator Services Security Context

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G communication systems face challenges in managing security for restricted local operator services, particularly in providing network access to unauthenticated user equipment and ensuring seamless operation during authentication failures or limited service states.

Innovation Solution

The implementation of a method that maintains a list of networks supporting restricted local operator services, checks conditions for access, and initiates a search to find suitable networks, sending security algorithm requests, and establishing a security context for unauthenticated user equipment to access these services, ensuring acceptance by the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If unauthenticated user equipment is allowed to access restricted local operator services, then service availability is improved, but security risk increases

Engineering Contradiction:
Improveservice availabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments network services into authenticated services and restricted local operator services (RLOS). Unauthenticated UE can access only RLOS through a separate access path, while authenticated services remain protected. This segmentation allows service availability improvement without compromising overall security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism where the network establishes a controlled security context for unauthenticated UE accessing RLOS. This intermediary security framework mediates between the need for service availability and security requirements, allowing limited access without full authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication procedures are enforced for all network access, then security is improved, but access time increases

Engineering Contradiction:
ImprovesecurityVSAvoidaccess time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial authentication action by allowing unauthenticated UE to access RLOS without completing full authentication procedures. The authentication process is made optional or partial for RLOS access, reducing access time while maintaining sufficient security through the specialized RLOS access mechanism.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If a comprehensive network search is performed to find suitable networks for RLOS, then service reliability is improved, but processing time increases

Engineering Contradiction:
Improveservice reliabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-configuring and maintaining a list of networks that support RLOS. This pre-prepared information allows the UE to quickly find suitable networks without performing comprehensive real-time searches, thus improving service reliability while minimizing processing time.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If security algorithms are negotiated with unauthenticated UE, then security context establishment is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity context establishmentVSAvoidprotocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the parameters of security negotiation by using simplified security algorithm selection specifically for RLOS access. Instead of full authentication-based security negotiation, the system uses predetermined or simplified security parameters for unauthenticated UE, improving security context establishment while reducing protocol complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11563743B2Security management for restricted local operator services in communication system
Publication Date: 2023.01.24 NOKIA TECHNOLOGIES OY
  • US11563743B2 patent drawing
  • US11563743B2 patent drawing
  • US11563743B2 patent drawing

AI summary

Techniques for security management in communication systems are provided. For example, a method comprises maintaining a list of networks that support access for a set of restricted local operator services, checking whether a set of conditions for triggering access to the set of restricted local operator services is satisfied, receiving a request for access to the set of restricted local operator services, and initiating, upon satisfaction of the set of conditions, a search of the list of networks to find a network for access to the set of restricted local operator services.