Security Edge Protection Proxy Selective Application Layer Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Security management in 5G communication systems faces challenges due to the need for enhanced security protocols and efficient application layer security mechanisms, particularly in Service-Based Architecture (SBA) across different network functions and edge protection proxy elements, where varying types of data require different security treatments.

Innovation Solution

Configuring security edge protection proxy elements to apply different types of application layer security to information elements, including end-to-end encryption and integrity protection, with the ability to identify and selectively apply security operations based on message indicators or provisioning information, and negotiating security profiles and keys with peer proxy elements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If uniform security protocols are applied to all information elements, then security management is simplified, but security effectiveness is reduced because different data types require different security treatments

Engineering Contradiction:
Improvesecurity management complexityVSAvoidsecurity effectiveness
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent applies different security protocols to different information elements based on their specific requirements. The SEPP identifies sensitive information elements (such as SUPI, SUCI, authentication vectors) and applies appropriate security treatments (encryption, integrity protection, anonymity) to each type, rather than applying a uniform security protocol to all data. This resolves the contradiction by making security management tailored to local needs while maintaining overall system effectiveness.

Inventive Principle:
Principle #3Local quality

2Reliability

If application layer security is applied to all information elements, then security coverage is maximized, but processing overhead increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidmessage processing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the message into different information elements and identifies which ones require security treatment. The SEPP parses the HTTP message, identifies sensitive information elements based on their types (e.g., subscriber identity, authentication data, location information), and applies security protocols only to those specific elements rather than encrypting or protecting the entire message. This segmentation approach maintains comprehensive security coverage for sensitive data while reducing processing overhead by excluding non-sensitive elements from security operations.

Inventive Principle:
Principle #1Segmentation

3Reliability

If different security protocols are applied to different information elements, then security effectiveness is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidsecurity protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary identification and classification of information elements before applying security protocols. The SEPP is pre-configured with knowledge of which information element types require which security treatments (e.g., SUPI requires encryption and anonymity, authentication vectors require integrity protection). This preliminary action allows the system to efficiently apply the correct security protocol without complex real-time decision-making, thereby improving security effectiveness while managing system complexity through pre-established security policies.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3753227B1Security management in communication systems with security-based architecture using application layer security
Publication Date: 2024.10.02 NOKIA TECHNOLOGIES OY
  • EP3753227B1 patent drawingFigure 1
  • EP3753227B1 patent drawingFigure 2
  • EP3753227B1 patent drawingFigure 3

AI summary

In a communication system comprising a first network operatively coupled to a second network, wherein the first network comprises a first security edge protection proxy element operatively coupled to a second security edge protection proxy element of the second network; the method comprises configuring at least a given one of the first and second security edge protection proxy elements to apply application layer security to one or more information elements in a received message from a network function before sending the message to the other one of the first and second security edge protection proxy elements.