Secure Unit Descriptors for Reliable URSP Session Creation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems face issues with tampered or forged application descriptors in session creation, leading to network reliability problems due to confusion in session establishment.

Innovation Solution

A method for session creation involving a user equipment (UE) that reads application descriptors bound to a signing certificate or digital fingerprint from a secure unit, using these descriptors in a UE route selection policy (URSP) rule to prevent tampering and ensure network stability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If application descriptors are stored in non-secure memory for session creation, then session creation speed is improved, but security and reliability deteriorate due to tampering and forging risks

Engineering Contradiction:
Improvesession creation speedVSAvoidsession creation reliability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent segments the storage system into two parts: a secure unit for storing application descriptors bound to signing certificates, and non-secure memory for temporary access. This segmentation allows the system to maintain security while enabling fast session creation by reading from the secure unit only when needed and binding descriptors temporarily to sessions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary actions by pre-storing application descriptors bound to signing certificates in the secure unit before session creation. This preliminary binding and secure storage eliminates the need for real-time security verification during session creation, thus maintaining both security and speed.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If application descriptors are bound to signing certificates in secure storage, then security and reliability are improved, but device complexity increases due to secure unit requirements

Engineering Contradiction:
Improvesession creation reliabilityVSAvoidstorage system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the secure unit multi-functional by using it not only for storing application descriptors but also for storing signing certificates and digital fingerprints. This universal usage of the secure unit reduces the need for separate dedicated security storage, thereby reducing overall device complexity while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent creates temporary copies of application descriptors from the secure unit and binds them to sessions in non-secure memory. This copying mechanism allows the secure unit to remain compact and simple while still providing secure access to multiple applications, as each session receives only the necessary copied data.

Inventive Principle:
Principle #26Copying

3Ease of operation

If application descriptors are stored without binding to signing certificates, then ease of operation is improved, but security deteriorates due to inability to prevent tampering

Engineering Contradiction:
Improvedescriptor access simplicityVSAvoidanti-tampering capability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces the secure unit as an intermediary between the application descriptors and the session creation process. The secure unit automatically verifies the binding between application descriptors and signing certificates, providing a simple interface for applications while maintaining strong security verification in the background.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements self-service by having the secure unit automatically manage the binding verification between application descriptors and signing certificates. The system autonomously handles security checks without requiring manual intervention from applications, thus maintaining ease of operation while ensuring security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12408035B2Method for session creation and related equipment
Publication Date: 2025.09.02 BEIJING SPREADTRUM HI TECH COMM TECH CO LTD
  • US12408035B2 patent drawing
  • US12408035B2 patent drawing
  • US12408035B2 patent drawing

AI summary

A method for session creation is provided. The method includes: reading from a secure unit application descriptors1 of a first application, where the application descriptors1 is bound to a signing certificate of the first application or a digital fingerprint of the signing certificate; and creating a session by using the application descriptors1 as application descriptors in a UE route selection policy (URSP) rule.