Security-Aware Network Node Selection for Shared Infrastructure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users of network services are vulnerable to security attacks due to shared network infrastructure, where malicious parties can compromise the security of different parties' software.

Innovation Solution

A method for selecting network functions (NFs) based on security infrastructure characteristics, including secure boot, remote attestation, and other security parameters, to ensure that data handling meets specific security criteria.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If network infrastructure is shared among multiple users, then resource utilization and cost efficiency are improved, but security vulnerability increases due to potential compromise by malicious parties

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the network function selection process by introducing security infrastructure characteristics as a distinct selection criterion. Nodes are evaluated and segmented into different categories based on their security attributes (secure boot, remote attestation, etc.), allowing the system to select appropriate nodes for specific data handling tasks while maintaining shared infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by requiring different security characteristics for different network functions or data types. Instead of uniform security requirements across the entire system, the solution tailors security criteria to specific local needs - certain functions may require secure boot while others may require remote attestation, optimizing both security and resource utilization.

Inventive Principle:
Principle #3Local quality

2Reliability

If security criteria are strictly enforced for node selection, then data security is improved, but node selection complexity and system overhead increase

Engineering Contradiction:
Improvedata securityVSAvoidnode selection complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by having nodes pre-register their security infrastructure characteristics with the network repository function (NRF) before actual data handling occurs. Security attributes such as secure boot status, remote attestation capabilities, and other security parameters are established and stored in advance, so that when node selection is needed, the decision can be made quickly based on pre-collected information rather than performing complex security evaluations at selection time.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive security infrastructure characteristics are collected and verified, then security reliability is improved, but information processing time and system overhead increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidinformation processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent collects and verifies security infrastructure characteristics in advance during node registration, rather than at the time of data handling. The NRF stores these pre-verified security attributes, enabling rapid node selection based on pre-collected information. This eliminates the need for time-consuming security evaluations during actual data processing operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by having the NRF store copies of security infrastructure characteristics and node information. Instead of repeatedly querying nodes or performing full security verification for each data handling operation, the system uses pre-stored copies of security attributes from the NRF, significantly reducing information processing time while maintaining security reliability.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20250294353A1First Node, Second Node, Third Node, Communications System and Methods Performed Thereby for Handling Security
Publication Date: 2025.09.18 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20250294353A1 patent drawing
  • US20250294353A1 patent drawing
  • US20250294353A1 patent drawing

AI summary

A computer-implemented method. performed by a first node (111). The method is for handling security. The first node (111) operates in a communications system (100). The first node (111) determines (403). out of one or more second nodes (112) operating in the communications system (100), which one or more selected second nodes fulfil one or more security criteria to handle data. The determining (403) is based on a respective first indication indicating one or more respective characteristics of a respective security infrastructure of the one or more selected second nodes. The first node (111) sends (405) a request to establish a connection to one of the selected second nodes.