Secure Enclave for 5G URSP Rule Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The 5G user equipment (UE) is vulnerable to malicious tampering and modification of User Equipment Route Selection Policy (URSP) rules, which can lead to cyber-attacks, unauthorized access, and distributed denial of service (DDOS) attacks, compromising the security of the 5G network and its infrastructure.

Innovation Solution

A method and system for validating and securing URSP rules by verifying their content and signature using a hashed message authentication code (HMAC) or digital signature, ensuring they have not been altered, and updating them if necessary, with the UE accessing the core network for rule updates when discrepancies are detected, and integrating these rules into a secure enclave for protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If URSP rules are stored in the UE device to enable dynamic traffic routing to network slices, then network slicing functionality and service flexibility are improved, but the device becomes vulnerable to malicious tampering and modification of the rules

Engineering Contradiction:
Improvenetwork slicing functionalityVSAvoidURSP rule integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the URSP rule storage into two distinct locations: a first location (secure enclave) that stores only the signature information, and a second location that stores the full URSP rules. This segmentation allows the device to benefit from having URSP rules locally available for dynamic routing while protecting the critical signature information in a secure environment, thus resolving the contradiction between functionality and integrity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a secure enclave as an intermediary component between the URSP rule storage and the processing system. The secure enclave acts as a trusted mediator that verifies the signature of URSP rules before they are executed, ensuring that even if the rules in the second location are tampered with, the system can detect the modification and reject the malicious rules, thus maintaining rule integrity while enabling flexible routing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If URSP rules are made accessible at the device level for intelligent traffic routing, then quality of experience and service access are improved, but the device opens security vulnerabilities to cyber-attacks and unauthorized access

Engineering Contradiction:
Improveservice accessVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary verification action by checking the signature of URSP rules against the stored signature information in the secure enclave before the rules are executed. This preliminary check ensures that only authenticated and unmodified rules are applied for traffic routing, preventing malicious rules from compromising service access while maintaining ease of operation for legitimate services.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies preliminary anti-action by pre-storing the signature information in the secure enclave before URSP rules are downloaded or modified. This pre-established security reference enables the system to proactively detect and block tampered rules, countering potential cyber-attacks before they can compromise service access or cause harm.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If signature verification of URSP rules is implemented in the UE, then protection against malicious tampering is improved, but device complexity and processing overhead increase

Engineering Contradiction:
ImproveURSP rule securityVSAvoidverification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the critical signature verification function into a separate secure enclave component, isolating it from the main URSP rule processing system. This extraction allows the verification mechanism to be implemented using dedicated security hardware or trusted execution environments, reducing the complexity burden on the main device processor while maintaining high reliability through specialized security processing.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11902152B2Secure enclave of UE route selection policy rules in the 5G device or network slicing
Publication Date: 2024.02.13 T MOBILE INNOVATIONS LLC
  • US11902152B2 patent drawing
  • US11902152B2 patent drawing
  • US11902152B2 patent drawing

AI summary

System and method for creating a secure enclave for User Equipment Route Selection Policy (URSP) rules in User Equipment (UE) in 5G to prevent malicious tampering and modification of the URSP rules. When the URSP rules are changed, a request is sent to receive a new set of URSP rules or receive an update of the URSP rules.