Security Function Network Element Access Control Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The flexibility of controlling IoT device access to networks in 5G systems is limited when using methods adapted from 4G systems, necessitating a more flexible, real-time, and automated approach to manage security threats and network access.

Innovation Solution

A method involving a security function network element that detects security threats and sends indications to a storage function network element to control terminal access, using automatic processing logic to allow or forbid access, enhancing flexibility and automation compared to manual administrator configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If manual administrator configuration of access lists is used, then security control is implemented, but flexibility and real-time response are poor

Engineering Contradiction:
Improveflexibility of access controlVSAvoidautomation of access control
Core Design Contradiction:
Adaptability or versatilityVSExtent of automation

Solution Approach 1:

The system enables self-service automation where the network element autonomously detects security threats, determines access control decisions, and sends indications to control terminals without requiring manual administrator intervention. This automated self-service mechanism resolves the contradiction by eliminating the need for manual configuration while maintaining security control, thereby improving flexibility and real-time response capability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The network element performs preliminary security threat detection and access control decision-making before actual access requests occur. By proactively identifying security threats and pre-determining access control actions, the system can rapidly respond to security events without waiting for manual administrator responses, thus improving both flexibility and automation.

Inventive Principle:
Principle #10Preliminary action

2Speed

If automated security threat detection is implemented, then real-time control is improved, but system complexity increases

Engineering Contradiction:
Improvereal-time control speedVSAvoidcomplexity of security control system
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent extracts the security threat detection and access control decision-making functions into a dedicated network element. This separation isolates the complex automated security processing from the core network infrastructure, enabling real-time control through specialized hardware or software while managing system complexity by containing it within a specific component rather than distributing it throughout the entire system.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3761590B1Method for controlling terminal to access network, and network element
Publication Date: 2023.06.28 HUAWEI TECH CO LTD
  • EP3761590B1 patent drawingFigure 1A~1B
  • EP3761590B1 patent drawingFigure 2~3
  • EP3761590B1 patent drawingFigure 4~5A

AI summary

A method for controlling access of a terminal to a network and a network element belong to a field of communications technologies. The method includes: detecting, by a security function network element, whether a target terminal is exposed to a security threat; sending, by the security function network element, a message to a storage function network element based on a detection result, where the message includes device information and network access indication information, the device information is used to indicate at least one terminal including the target terminal, and the network access indication information is used to instruct to allow or forbid the at least one terminal to access a network; and updating, by the storage function network element, network access permission information of the at least one terminal based on the device information and the network access indication information, where the network access permission information is used to indicate whether the at least one terminal is allowed to access the network. In solutions provided in this application, the security function network element outputs an allowed or forbidden indication to the storage function network element by using an automatic processing logic of the security function network element, and the storage function network element controls, based on the foregoing indication, access of the terminal to the network. This is more flexible, real-time, and automated than a manual configuration mode of an administrator.