Secure Unit Descriptors for Reliable URSP Session Creation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems face issues with tampered or forged application descriptors in session creation, leading to network reliability problems due to confusion in session establishment.
Innovation Solution
A method for session creation involving a user equipment (UE) that reads application descriptors bound to a signing certificate or digital fingerprint from a secure unit, using these descriptors in a UE route selection policy (URSP) rule to prevent tampering and ensure network stability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If application descriptors are stored in non-secure memory for session creation, then session creation speed is improved, but security and reliability deteriorate due to tampering and forging risks
Solution Approach 1:
The patent segments the storage system into two parts: a secure unit for storing application descriptors bound to signing certificates, and non-secure memory for temporary access. This segmentation allows the system to maintain security while enabling fast session creation by reading from the secure unit only when needed and binding descriptors temporarily to sessions.
Solution Approach 2:
The patent performs preliminary actions by pre-storing application descriptors bound to signing certificates in the secure unit before session creation. This preliminary binding and secure storage eliminates the need for real-time security verification during session creation, thus maintaining both security and speed.
2Reliability
If application descriptors are bound to signing certificates in secure storage, then security and reliability are improved, but device complexity increases due to secure unit requirements
Solution Approach 1:
The patent makes the secure unit multi-functional by using it not only for storing application descriptors but also for storing signing certificates and digital fingerprints. This universal usage of the secure unit reduces the need for separate dedicated security storage, thereby reducing overall device complexity while maintaining security.
Solution Approach 2:
The patent creates temporary copies of application descriptors from the secure unit and binds them to sessions in non-secure memory. This copying mechanism allows the secure unit to remain compact and simple while still providing secure access to multiple applications, as each session receives only the necessary copied data.
3Ease of operation
If application descriptors are stored without binding to signing certificates, then ease of operation is improved, but security deteriorates due to inability to prevent tampering
Solution Approach 1:
The patent introduces the secure unit as an intermediary between the application descriptors and the session creation process. The secure unit automatically verifies the binding between application descriptors and signing certificates, providing a simple interface for applications while maintaining strong security verification in the background.
Solution Approach 2:
The patent implements self-service by having the secure unit automatically manage the binding verification between application descriptors and signing certificates. The system autonomously handles security checks without requiring manual intervention from applications, thus maintaining ease of operation while ensuring security.
Data Source
AI summary
A method for session creation is provided. The method includes: reading from a secure unit application descriptors1 of a first application, where the application descriptors1 is bound to a signing certificate of the first application or a digital fingerprint of the signing certificate; and creating a session by using the application descriptors1 as application descriptors in a UE route selection policy (URSP) rule.


