Security Policy Vector Distribution in Mobile Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for updating security algorithms in communication networks are time-consuming and expensive, and current methods for distributing security policies often degrade the entropy of signalling messages or restrict their use, limiting flexibility and compatibility across different network environments.

Innovation Solution

A method and apparatus for generating and distributing security policy vectors between home and visited communication networks, allowing for the secure and flexible selection of security algorithms and functions without affecting existing signalling messages, enabling both networks to influence the security policy and ensuring compliance with both HPLMN and VPLMN policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security algorithms are removed and replaced in each radio base station, then security strength is improved, but the procedure becomes very time-consuming and expensive

Engineering Contradiction:
Improvesecurity strengthVSAvoidupdate time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts the security algorithm policy distribution function from the radio base station hardware and relocates it to the network core (MME and HSS). The HSS stores security policy vectors and generates integrity protection tags, while the MME distributes selected security policies to terminals. This extraction allows security algorithm updates to be performed through software updates in the network core rather than hardware updates in each radio base station, dramatically reducing update time and cost while maintaining security strength.

Inventive Principle:
Principle #2Taking out (Extraction)

2Adaptability or versatility

If a part of the RAND value is used to define acceptable security algorithms, then security policy control is improved, but the entropy/randomness of the RAND value decreases

Engineering Contradiction:
Improvesecurity policy controlVSAvoidentropy of RAND value
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent segments the security policy control function from the authentication random value (RAND). Instead of embedding security algorithm selection within the RAND value bits, the system uses separate security policy vectors stored in the HSS that independently define acceptable security algorithms. The RAND value retains its full entropy for authentication purposes, while security policy control is achieved through separate integrity protection tags generated from the security policy vectors. This segmentation eliminates the entropy loss while maintaining security policy control.

Inventive Principle:
Principle #1Segmentation

3Device complexity

If the HPLMN controls the security algorithm policy mainly, then security policy generation is simplified, but the VPLMN operator has difficulty to influence the security algorithm policy

Engineering Contradiction:
Improvepolicy control structureVSAvoidVPLMN influence
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a new dimension for security policy control by implementing a two-vector system: the HPLMN provides the first security policy vector (Ph) containing home network security requirements, while the VPLMN provides the second security policy vector (Pv) containing visited network security requirements. The MME combines these vectors to determine the final security policy, allowing both operators to influence the security algorithm selection. This dimensional expansion from single-vector to two-vector control enables collaborative policy-making while maintaining clear responsibility分工 between HPLMN and VPLMN operators.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS8819765B2Security policy distribution to communication terminals
Publication Date: 2014.08.26 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US8819765B2 patent drawing
  • US8819765B2 patent drawing
  • US8819765B2 patent drawing

AI summary

A method and arrangement for distributing a security policy to a communication terminal having an association with a home communication network, but being present in a visited communication network. The home communication network generates its own preferred security policy Ph and the visited communication network generates its own preferred security policy Pv. A communication network entity in the visited communication network combines the security policies and selects security algorithms and/or functions to apply from the combined security policy. By generating security policy vectors of both networks and combining them before the security algorithms are selected, both networks are able to influence the selection without requiring the use of signaling messages.