Security Negotiation in Service Based Architectures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity of security solutions for the N32 reference point in 3GPP Service Based Architecture (SBA) poses challenges, particularly in Rel-15, where a partial security solution deployed may be difficult to migrate to a full solution in Rel-16, risking bidding down attacks and inadequate security.

Innovation Solution

Integrity protected security capability negotiation between Secure Edge Protection Proxies (SEPPs) through mutual authentication and key agreement, allowing selection of appropriate security mechanisms over the N32 reference point, thereby preventing bidding down attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If a partial security solution is deployed in Rel-15, then deployment complexity is reduced and implementation is easier, but security reliability is compromised and migration to full solution in Rel-16 becomes difficult

Engineering Contradiction:
Improvedeployment easeVSAvoidsecurity reliability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent implements dynamic security capability negotiation between SEPPs, allowing the security mechanism to be adaptively selected and updated based on mutual authentication results. The system can dynamically transition from partial to full security solutions without fixed deployment constraints, resolving the contradiction between deployment ease and security reliability by making the security level flexible rather than static.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the security parameter from fixed to negotiable by introducing security capability negotiation protocols. SEPPs exchange security capability information and mutually authenticate to determine the appropriate security mechanism, allowing the security level parameter to be adjusted based on actual conditions rather than being locked into a partial solution for deployment simplicity.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If security capability negotiation is implemented between SEPPs, then security reliability is improved and bidding down attacks are prevented, but device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal security negotiation framework that can handle multiple security mechanisms (TLS, IPsec, etc.) through a single standardized protocol. The SEPPs use a common authentication and capability exchange mechanism that works across different security technologies, reducing the need for separate complex implementation for each security type and thereby managing device complexity while maintaining high security reliability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary security capability negotiation protocol between SEPPs that mediates the selection and configuration of security mechanisms. This intermediary layer handles the complexity of mutual authentication and capability matching, shielding the core security implementation from direct complexity while ensuring reliable security through standardized negotiation procedures.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If integrity protected connection is established for security negotiation, then security mechanism selection is secured against attacks, but communication overhead increases

Engineering Contradiction:
Improvenegotiation securityVSAvoidcommunication overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent establishes integrity-protected connections and performs mutual authentication in advance during the security capability negotiation phase, before actual signaling communication begins. This preliminary security setup prevents attacks during negotiation while allowing subsequent communication to proceed efficiently without repeated authentication overhead, balancing negotiation security with communication efficiency.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3756326B1Security negotiation in service based architectures (SBA)
Publication Date: 2021.08.04 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP3756326B1 patent drawingFigure 1
  • EP3756326B1 patent drawingFigure 2
  • EP3756326B1 patent drawingFigure 3

AI summary

The disclosure provides techniques for negotiating security mechanisms between security gateways (102A, 102B). In these techniques, an initiating security gateway (102A) sends (302) a request message to a responding security gateway (102B) over a first connection established between the security gateways. The first connection provides integrity protection for 5 the messages. The request message includes one or more security mechanisms supported by the initiating security gateway. Upon receipt, the responding security gateway selects (406) one of the security mechanisms and transmits (408) a response message to the initiating security gateway indicating the selected security mechanism. Signaling messages are then communicated (310, 412) between the security gateways using the selected security 10 mechanism.