Security Decision Negotiation in 5G Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing security decision negotiation method in 5G communication systems is not flexible enough to accommodate various types of terminal devices and third-party devices, limiting the ability to negotiate security decisions effectively.
Innovation Solution
A method and network element that determine a security decision based on the security requirements of a requester and the security capabilities of a capability provider, allowing for flexible negotiation and participation from both parties, and utilizing a distributed ledger for secure storage and retrieval of security decisions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the existing security decision negotiation method is used, then the network element can send security mode command messages, but the flexibility to accommodate various types of terminal devices and third-party devices is insufficient
Solution Approach 1:
The patent segments the security decision negotiation process into distinct functional components: capability provider, requester, and first network element. Each component has specific responsibilities (providing capabilities, expressing requirements, and making decisions), which simplifies the overall complexity while enabling flexible accommodation of various device types through standardized interfaces.
Solution Approach 2:
The patent creates a universal security decision negotiation framework that can handle multiple device types (terminal devices, third-party devices) through a common set of protocols and message formats. The first network element can negotiate security decisions with any capability provider using the standardized capability information element structure, achieving multi-functionality without requiring device-specific handling.
2Reliability
If the terminal device sets encryption and integrity protection algorithms unilaterally, then the security decision is straightforward, but the participation and reasonableness of the requester is reduced
Solution Approach 1:
The patent implements a feedback mechanism where the capability provider provides security capability information to the first network element, which then formulates security decisions based on both the capability information and the requester's requirements. This feedback loop ensures the requester's participation is captured and reflected in the final security decision, improving both reasonableness and operational fairness.
Solution Approach 2:
The patent changes the parameter of decision-making from unilateral device setting to a negotiated decision based on multiple parameters: capability provider's security capabilities, requester's security requirements, and network element's formulation. This multi-parameter approach ensures the security decision reflects the needs and capabilities of all parties involved.
3Reliability
If security requirements and capabilities are stored traditionally, then the system is simple, but the security of stored information is insufficient
Solution Approach 1:
The patent introduces a distributed ledger as an intermediary storage system for security requirements and capabilities. This intermediary layer provides enhanced security through its distributed and immutable nature, while the first network element acts as a mediator that queries and utilizes this storage without requiring direct integration into the core network architecture, thus balancing security improvement with acceptable complexity.
Data Source
AI summary
A security decision negotiation method and a network element are applicable to various communication systems, such as an IoT system, an LTE system, a 5G system, an MTC system, an M2M system, a D2D system, a V2X system, and a WLAN system (such as Wi-Fi). The method includes: A first network element determines a security decision based on a security requirement of a requester and a security capability of a capability provider, and the first network element sends a message including the security decision. In embodiments of this application, flexibility of security


