Secure Enclave for 5G URSP Rule Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The 5G user equipment (UE) is vulnerable to malicious tampering and modification of User Equipment Route Selection Policy (URSP) rules, which can lead to cyber-attacks, unauthorized access, and distributed denial of service (DDOS) attacks, compromising the security of the 5G network and its infrastructure.
Innovation Solution
A method and system for validating and securing URSP rules by verifying their content and signature using a hashed message authentication code (HMAC) or digital signature, ensuring they have not been altered, and updating them if necessary, with the UE accessing the core network for rule updates when discrepancies are detected, and integrating these rules into a secure enclave for protection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If URSP rules are stored in the UE device to enable dynamic traffic routing to network slices, then network slicing functionality and service flexibility are improved, but the device becomes vulnerable to malicious tampering and modification of the rules
Solution Approach 1:
The patent segments the URSP rule storage into two distinct locations: a first location (secure enclave) that stores only the signature information, and a second location that stores the full URSP rules. This segmentation allows the device to benefit from having URSP rules locally available for dynamic routing while protecting the critical signature information in a secure environment, thus resolving the contradiction between functionality and integrity.
Solution Approach 2:
The patent introduces a secure enclave as an intermediary component between the URSP rule storage and the processing system. The secure enclave acts as a trusted mediator that verifies the signature of URSP rules before they are executed, ensuring that even if the rules in the second location are tampered with, the system can detect the modification and reject the malicious rules, thus maintaining rule integrity while enabling flexible routing.
2Ease of operation
If URSP rules are made accessible at the device level for intelligent traffic routing, then quality of experience and service access are improved, but the device opens security vulnerabilities to cyber-attacks and unauthorized access
Solution Approach 1:
The patent implements preliminary verification action by checking the signature of URSP rules against the stored signature information in the secure enclave before the rules are executed. This preliminary check ensures that only authenticated and unmodified rules are applied for traffic routing, preventing malicious rules from compromising service access while maintaining ease of operation for legitimate services.
Solution Approach 2:
The patent applies preliminary anti-action by pre-storing the signature information in the secure enclave before URSP rules are downloaded or modified. This pre-established security reference enables the system to proactively detect and block tampered rules, countering potential cyber-attacks before they can compromise service access or cause harm.
3Reliability
If signature verification of URSP rules is implemented in the UE, then protection against malicious tampering is improved, but device complexity and processing overhead increase
Solution Approach 1:
The patent extracts the critical signature verification function into a separate secure enclave component, isolating it from the main URSP rule processing system. This extraction allows the verification mechanism to be implemented using dedicated security hardware or trusted execution environments, reducing the complexity burden on the main device processor while maintaining high reliability through specialized security processing.
Data Source
AI summary
System and method for creating a secure enclave for User Equipment Route Selection Policy (URSP) rules in User Equipment (UE) in 5G to prevent malicious tampering and modification of the URSP rules. When the URSP rules are changed, a request is sent to receive a new set of URSP rules or receive an update of the URSP rules.


