Per-Slice Security Separation in Mobile Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile communication networks cannot apply different security algorithms or settings based on specific security requirements for each network slice, and a single terminal cannot have different security settings for multiple data bearers simultaneously, which is a limitation in supporting diverse security needs for various services.
Innovation Solution
A method and apparatus for a mobile network that includes a security device to store and transmit slice-specific security requirements, and a network device to request and select appropriate security algorithms based on these requirements for each network slice, enabling per-slice security settings.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a single security algorithm is applied to all network slices, then system simplicity is maintained, but security requirements for different services cannot be differentiated
Solution Approach 1:
The patent segments the security management system into multiple components: a security device that stores slice-specific security requirements, a network device that requests and receives security information, and a mapping mechanism that associates slice IDs with security algorithms. This segmentation allows different security algorithms to be applied to different network slices while maintaining manageable system complexity through clear division of responsibilities.
Solution Approach 2:
The patent introduces a security device as an intermediary component between the network device and the security algorithms. This intermediary stores and manages slice security requirements, receiving requests from network devices and providing appropriate security algorithm selections. The intermediary abstracts the complexity of managing multiple security algorithms, allowing network devices to simply request security information without directly managing the complexity of multiple security policies.
2Reliability
If multiple security algorithms are supported for different slices, then diverse service security needs are met, but the system complexity increases significantly
Solution Approach 1:
The patent implements preliminary action by having the security device pre-store slice security requirements and algorithm mappings before actual network operations. When a network slice is created or configured, the corresponding security requirements and algorithm associations are established in advance in the security device. This pre-configured information is then quickly retrieved during runtime through simple ID matching, avoiding the need for complex real-time security algorithm selection and configuration.
Solution Approach 2:
The patent uses parameter changes by introducing a slice ID as a key parameter that links network slices to their specific security algorithms. Instead of managing complex security configurations directly, the system changes the approach to using simple parameter matching: the network device includes a slice ID in its request, the security device uses this ID to retrieve the corresponding security algorithm from stored mappings, and the appropriate algorithm is selected based on this parameter association. This transforms a complex configuration problem into a simple parameter lookup operation.
3Adaptability or versatility
If per-slice security settings are implemented, then security flexibility for multiple services is improved, but current network architecture limitations prevent implementation
Solution Approach 1:
The patent applies universality by designing a security management mechanism that can serve multiple network slices through a single, unified security device. This security device stores security requirements for multiple slices and can respond to requests from any network device in the system. The same security device and basic interaction protocol work universally across all slices and network devices, providing per-slice security differentiation without requiring separate security management systems for each slice or complex architectural changes.
Data Source
AI summary
A mobile network system comprises a security device and a network device. The security device stores slice security requirements which are different for each slice ID (identification). The slice ID indicates a network slice in a core network. The network device transmits, to the security device, a Slice Security Request including the slice ID. The network device receives, from the security device, a Slice Security Response including the slice security requirements related to the slice ID. The network device selects, based on the slice security requirements, a security algorithm for the network slice.


