Security Service Orchestration Function for 5G S-SLA Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G network architectures lack standardized security orchestration and management capabilities, leading to difficulties in interoperability, stability, and cost issues due to vendor-specific interfaces, and do not allow for dynamic security requirements to be set or monitored effectively, resulting in inadequate security posture transparency for users and service providers.

Innovation Solution

A Security Service Orchestration Function (SSOF) is introduced to provide standardized interfaces and reference points for security orchestration, enabling the negotiation and enforcement of Security Service Level Agreements (S-SLAs) across multiple public land mobile networks and enterprises, ensuring consistent and unified security attributes are provided and monitored.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If vendor-specific non-standard interfaces are used for security management, then implementation flexibility is improved, but interoperability and system stability deteriorate

Engineering Contradiction:
Improveimplementation flexibilityVSAvoidinteroperability and system stability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a universal security service orchestration function that provides standardized interfaces for security management across different network functions and vendors. This universal framework enables multiple security operations (orchestration, management, monitoring) through a common set of interfaces, ensuring interoperability while maintaining vendor-specific implementation flexibility through the service-based architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Device complexity

If security orchestration is left outside 3GPP scope, then standardization complexity is reduced, but security management capabilities and transparency deteriorate

Engineering Contradiction:
Improvestandardization complexityVSAvoidsecurity posture transparency
Core Design Contradiction:
Device complexityVSLoss of information

Solution Approach 1:

The patent introduces a security service orchestration function as an intermediary layer between 3GPP network functions and external security management systems. This intermediary provides standardized interfaces for security orchestration while maintaining the boundaries of 3GPP architecture, enabling security posture transparency and dynamic security requirements without increasing core standardization complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments security management into distinct functional components: security service orchestration function, security management interfaces, and network function security capabilities. This segmentation allows security orchestration to be handled separately from core 3GPP specifications, enabling enhanced security transparency and management capabilities without complicating the core network architecture.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If static security service level agreements are used, then agreement simplicity is improved, but dynamic security requirement fulfillment deteriorates

Engineering Contradiction:
Improveagreement simplicityVSAvoiddynamic security requirement fulfillment
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent transforms static security service level agreements into dynamic agreements through the security service orchestration function. The system enables real-time negotiation, monitoring, and adjustment of security attributes and requirements, allowing security levels to adapt dynamically while maintaining structured agreement frameworks through standardized interfaces and service-based architecture.

Inventive Principle:
Principle #15Dynamics

4Device complexity

If security information is transferred as part of standard service orchestration, then integration simplicity is improved, but security risks and isolation challenges increase

Engineering Contradiction:
Improveintegration simplicityVSAvoidsecurity risks
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts security information transfer from standard service orchestration into a dedicated security service orchestration function. This separation isolates security-critical information flows from general service orchestration, reducing security risks and isolation challenges while maintaining integration simplicity through standardized interfaces and defined reference points between the security function and network functions.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20240323103A1Security service orchestration function in a service-based architecture
Publication Date: 2024.09.26 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20240323103A1 patent drawing
  • US20240323103A1 patent drawing
  • US20240323103A1 patent drawing

AI summary

A method is implemented by a security service orchestration function (SSOF) in a communication infrastructure, that includes a plurality of PLMNs and a plurality of enterprises, for orchestration of a security service level agreement (S-SLA). The method includes receiving, by a SSOF in a HPLMN, a S-SLA request from one or more of the enterprises. Each S-SLA request includes a plurality of requirements. The HPLMN corresponds to one of the plurality of PLMNs. The method also includes converting each S-SLA request into a consistent and unified S-SLA offerable to each enterprise. The consistent and unified S-SLA includes security attributes that the HPLMN is capable of providing. The method also includes offering the consistent and unified S-SLA to each enterprise that submitted the S-SLA request. The method further includes transforming each S-SLA request from the enterprises into security policies and controls to be enforced within the HPLMN.