Security Policy Vector Distribution in Mobile Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for updating security algorithms in communication networks are time-consuming and expensive, and current methods for distributing security policies often degrade the entropy of signalling messages or restrict their use, limiting flexibility and compatibility across different network environments.
Innovation Solution
A method and apparatus for generating and distributing security policy vectors between home and visited communication networks, allowing for the secure and flexible selection of security algorithms and functions without affecting existing signalling messages, enabling both networks to influence the security policy and ensuring compliance with both HPLMN and VPLMN policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security algorithms are removed and replaced in each radio base station, then security strength is improved, but the procedure becomes very time-consuming and expensive
Solution Approach 1:
The patent extracts the security algorithm policy distribution function from the radio base station hardware and relocates it to the network core (MME and HSS). The HSS stores security policy vectors and generates integrity protection tags, while the MME distributes selected security policies to terminals. This extraction allows security algorithm updates to be performed through software updates in the network core rather than hardware updates in each radio base station, dramatically reducing update time and cost while maintaining security strength.
2Adaptability or versatility
If a part of the RAND value is used to define acceptable security algorithms, then security policy control is improved, but the entropy/randomness of the RAND value decreases
Solution Approach 1:
The patent segments the security policy control function from the authentication random value (RAND). Instead of embedding security algorithm selection within the RAND value bits, the system uses separate security policy vectors stored in the HSS that independently define acceptable security algorithms. The RAND value retains its full entropy for authentication purposes, while security policy control is achieved through separate integrity protection tags generated from the security policy vectors. This segmentation eliminates the entropy loss while maintaining security policy control.
3Device complexity
If the HPLMN controls the security algorithm policy mainly, then security policy generation is simplified, but the VPLMN operator has difficulty to influence the security algorithm policy
Solution Approach 1:
The patent introduces a new dimension for security policy control by implementing a two-vector system: the HPLMN provides the first security policy vector (Ph) containing home network security requirements, while the VPLMN provides the second security policy vector (Pv) containing visited network security requirements. The MME combines these vectors to determine the final security policy, allowing both operators to influence the security algorithm selection. This dimensional expansion from single-vector to two-vector control enables collaborative policy-making while maintaining clear responsibility分工 between HPLMN and VPLMN operators.
Data Source
AI summary
A method and arrangement for distributing a security policy to a communication terminal having an association with a home communication network, but being present in a visited communication network. The home communication network generates its own preferred security policy Ph and the visited communication network generates its own preferred security policy Pv. A communication network entity in the visited communication network combines the security policies and selects security algorithms and/or functions to apply from the combined security policy. By generating security policy vectors of both networks and combining them before the security algorithms are selected, both networks are able to influence the selection without requiring the use of signaling messages.


