Token-Based Application Identification for Secure 5G Route Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing 5G communication networks face challenges in securely identifying applications, allowing malicious applications to spoof genuine identities and gain access to operator-regulated resources due to the insecure nature of operating system application identifiers (OSAppIDs).

Innovation Solution

Implementing a secure token-based system where application service providers establish a trust relationship with the network operator, providing a token or Root of Trust (RoT) to ensure genuine application identification, which is integrated into User Equipment (UE) route selection policies to prevent application spoofing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional OSAppID identification is used, then application identification is simple, but security is compromised allowing malicious applications to spoof genuine identities

Engineering Contradiction:
Improveapplication identification securityVSAvoididentification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a token as an intermediary element between the application and the identification system. The token contains a secret value that serves as proof of genuine application identity, mediating the verification process between the application service provider and the network without requiring direct complex authentication mechanisms

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary action by provisioning the token with secret information in advance to the genuine application during installation or registration. This pre-established secret enables the application to later prove its identity without real-time complex verification, resolving the security-complexity contradiction

Inventive Principle:
Principle #10Preliminary action

2Reliability

If token-based identification is implemented, then application spoofing is prevented, but system complexity increases

Engineering Contradiction:
Improveapplication identity verificationVSAvoidroute selection policy complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by making the token verification specific to each application-service provider pair. Each genuine application receives a customized token with unique secret information tailored to its service provider, allowing targeted security verification without requiring universal complex authentication protocols across all applications

Inventive Principle:
Principle #3Local quality

3Reliability

If additional token information is added to URSP rules, then malicious applications are blocked, but processing overhead increases

Engineering Contradiction:
Improveoperator resource protectionVSAvoidroute selection processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts the security verification function from the main route selection process by using a standalone token mechanism. The token's secret value is separately verified against the URSP rule's expected secret, separating the authentication logic from route selection logic and minimizing processing overhead while maintaining resource protection

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP4322480B1Secure identification of applications in communication network
Publication Date: 2025.07.30 NOKIA TECHNOLOGIES OY
  • EP4322480B1 patent drawingFigure 1
  • EP4322480B1 patent drawingFigure 2
  • EP4322480B1 patent drawingFigure 3

AI summary

Techniques for securely identifying applications in a communication network are disclosed. For example, a method comprises receiving, at user equipment, a data item associated with an application program that is installed or being installed on the user equipment. The method further comprises storing, by the user equipment, the data item with an identifier of the application program. The method still further comprises utilizing, by the user equipment, the stored data item when deciding to apply a route selection rule for data traffic associated with the application program.