Secure Edge Connection Service for 5G RAN

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing 3GPP edge discovery and selection standards fail to provide a heightened level of security when requested by an edge application, particularly in scenarios involving sensitive operations or data.

Innovation Solution

A method is disclosed to trigger a secure edge connection service over a radio access network (RAN) between a known user equipment (UE) and a secure edge application server, by reading metadata from a centralized network user data store and enabling the secure edge connection service based on subscription information and policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing 3GPP edge discovery and selection standards are used, then network connectivity and edge resource discovery are enabled, but security protection for sensitive data is insufficient

Engineering Contradiction:
Improvesecurity protectionVSAvoidconnection configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-configuring secure edge connection parameters, policies, and authentication mechanisms before the actual connection is needed. The network pre-establishes security frameworks and the UE pre-loads necessary security credentials, so that when a secure edge connection is required, the security infrastructure is already in place and can be activated without complex real-time configuration.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism through the session manager and policy control function that mediates between the UE and the secure edge application server. This intermediary handles the complex security negotiation, authentication, and connection establishment automatically, shielding the UE from direct complexity while ensuring secure connections are properly configured.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a secure edge connection service is established, then end-to-end encryption and data protection are improved, but connection establishment time and network overhead increase

Engineering Contradiction:
Improvedata protectionVSAvoidconnection establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-establishing security frameworks, authentication credentials, and connection templates before the actual secure edge connection is needed. The network pre-configures security parameters and the UE pre-loads necessary security information, enabling rapid activation of secure connections without complex real-time negotiation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamics by allowing the secure edge connection to transition from an unsecured state to a secured state dynamically based on real-time needs. The connection can be quickly switched between secure and unsecured modes, and security parameters can be adjusted dynamically without requiring complete connection re-establishment, thus reducing the time penalty of secure connections.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250142507A1End-to-End (E2E) Secure Edge Application Service
Publication Date: 2025.05.01 T MOBILE INNOVATIONS LLC
  • US20250142507A1 patent drawing
  • US20250142507A1 patent drawing
  • US20250142507A1 patent drawing

AI summary

A method to trigger, by a RAN, a secure edge (SE) connection service over the RAN between a known user equipment (UE) and an SE application server is disclosed. The method comprises the RAN enabling an SE connection service. Responsive to the UE's registration request, the RAN registers the UE and loads associated user subscription data into a session manager (SM). Based on this data, an SE connection is configured within the RAN, and the SM establishes a PDU session between the UE and the SM by establishing a secure path between the UE and the SE application server over the configured SE connection between the UE and the RAN. The SM informs the UE of a resolver. After PDU session establishment, the resolver receives a resolution request from the UE and responds by sending an IP address directing the UE over the secure path to the SE application server.