Per-Slice Security Separation in Mobile Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile communication networks cannot apply different security algorithms or settings based on specific security requirements for each network slice, and a single terminal cannot have different security settings for multiple data bearers simultaneously, which is a limitation in supporting diverse security needs for various services.

Innovation Solution

A method and apparatus for a mobile network that includes a security device to store and transmit slice-specific security requirements, and a network device to request and select appropriate security algorithms based on these requirements for each network slice, enabling per-slice security settings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single security algorithm is applied to all network slices, then system simplicity is maintained, but security requirements for different services cannot be differentiated

Engineering Contradiction:
Improvesecurity differentiation capabilityVSAvoidsecurity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the security management system into multiple components: a security device that stores slice-specific security requirements, a network device that requests and receives security information, and a mapping mechanism that associates slice IDs with security algorithms. This segmentation allows different security algorithms to be applied to different network slices while maintaining manageable system complexity through clear division of responsibilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a security device as an intermediary component between the network device and the security algorithms. This intermediary stores and manages slice security requirements, receiving requests from network devices and providing appropriate security algorithm selections. The intermediary abstracts the complexity of managing multiple security algorithms, allowing network devices to simply request security information without directly managing the complexity of multiple security policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple security algorithms are supported for different slices, then diverse service security needs are met, but the system complexity increases significantly

Engineering Contradiction:
Improveservice-specific security assuranceVSAvoidsecurity configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by having the security device pre-store slice security requirements and algorithm mappings before actual network operations. When a network slice is created or configured, the corresponding security requirements and algorithm associations are established in advance in the security device. This pre-configured information is then quickly retrieved during runtime through simple ID matching, avoiding the need for complex real-time security algorithm selection and configuration.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses parameter changes by introducing a slice ID as a key parameter that links network slices to their specific security algorithms. Instead of managing complex security configurations directly, the system changes the approach to using simple parameter matching: the network device includes a slice ID in its request, the security device uses this ID to retrieve the corresponding security algorithm from stored mappings, and the appropriate algorithm is selected based on this parameter association. This transforms a complex configuration problem into a simple parameter lookup operation.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If per-slice security settings are implemented, then security flexibility for multiple services is improved, but current network architecture limitations prevent implementation

Engineering Contradiction:
Improveper-slice security configurationVSAvoidnetwork architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing a security management mechanism that can serve multiple network slices through a single, unified security device. This security device stores security requirements for multiple slices and can respond to requests from any network device in the system. The same security device and basic interaction protocol work universally across all slices and network devices, providing per-slice security differentiation without requiring separate security management systems for each slice or complex architectural changes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11134103B2Method of enabling slice security separation
Publication Date: 2021.09.28 NEC CORP
  • US11134103B2 patent drawing
  • US11134103B2 patent drawing
  • US11134103B2 patent drawing

AI summary

A mobile network system comprises a security device and a network device. The security device stores slice security requirements which are different for each slice ID (identification). The slice ID indicates a network slice in a core network. The network device transmits, to the security device, a Slice Security Request including the slice ID. The network device receives, from the security device, a Slice Security Response including the slice security requirements related to the slice ID. The network device selects, based on the slice security requirements, a security algorithm for the network slice.