Security Decision Negotiation in 5G Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing security decision negotiation method in 5G communication systems is not flexible enough to accommodate various types of terminal devices and third-party devices, limiting the ability to negotiate security decisions effectively.

Innovation Solution

A method and network element that determine a security decision based on the security requirements of a requester and the security capabilities of a capability provider, allowing for flexible negotiation and participation from both parties, and utilizing a distributed ledger for secure storage and retrieval of security decisions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the existing security decision negotiation method is used, then the network element can send security mode command messages, but the flexibility to accommodate various types of terminal devices and third-party devices is insufficient

Engineering Contradiction:
Improveflexibility to accommodate various terminal devicesVSAvoidcomplexity of security decision negotiation
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the security decision negotiation process into distinct functional components: capability provider, requester, and first network element. Each component has specific responsibilities (providing capabilities, expressing requirements, and making decisions), which simplifies the overall complexity while enabling flexible accommodation of various device types through standardized interfaces.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal security decision negotiation framework that can handle multiple device types (terminal devices, third-party devices) through a common set of protocols and message formats. The first network element can negotiate security decisions with any capability provider using the standardized capability information element structure, achieving multi-functionality without requiring device-specific handling.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If the terminal device sets encryption and integrity protection algorithms unilaterally, then the security decision is straightforward, but the participation and reasonableness of the requester is reduced

Engineering Contradiction:
Improvereasonableness of security decisionVSAvoidparticipation of requester in negotiation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a feedback mechanism where the capability provider provides security capability information to the first network element, which then formulates security decisions based on both the capability information and the requester's requirements. This feedback loop ensures the requester's participation is captured and reflected in the final security decision, improving both reasonableness and operational fairness.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent changes the parameter of decision-making from unilateral device setting to a negotiated decision based on multiple parameters: capability provider's security capabilities, requester's security requirements, and network element's formulation. This multi-parameter approach ensures the security decision reflects the needs and capabilities of all parties involved.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If security requirements and capabilities are stored traditionally, then the system is simple, but the security of stored information is insufficient

Engineering Contradiction:
Improvesecurity of security requirementsVSAvoidcomplexity of storage system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a distributed ledger as an intermediary storage system for security requirements and capabilities. This intermediary layer provides enhanced security through its distributed and immutable nature, while the first network element acts as a mediator that queries and utilizes this storage without requiring direct integration into the core network architecture, thus balancing security improvement with acceptable complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250126476A1Security decision negotiation method and network element
Publication Date: 2025.04.17 HUAWEI TECH CO LTD
  • US20250126476A1 patent drawing
  • US20250126476A1 patent drawing
  • US20250126476A1 patent drawing

AI summary

A security decision negotiation method and a network element are applicable to various communication systems, such as an IoT system, an LTE system, a 5G system, an MTC system, an M2M system, a D2D system, a V2X system, and a WLAN system (such as Wi-Fi). The method includes: A first network element determines a security decision based on a security requirement of a requester and a security capability of a capability provider, and the first network element sends a message including the security decision. In embodiments of this application, flexibility of security