Network Slice Security Profile Mapping for Secure Tunneling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Next Generation mobile networks, particularly 5G NR, face challenges in ensuring end-to-end security for IoT devices and enterprise applications due to the inability of low-cost IoT devices to support enhanced encryption and data integrity protection mechanisms, especially when data traverses public networks.

Innovation Solution

The establishment of a secure transport tunnel between a mobile network gateway and an application hosting server, provisioned across public networks, using a security profile that maps application and network slice identifiers to a selected security level, incorporating digital certificates or encryption keys, to ensure secure data transfer between user equipment and application servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If enhanced encryption and data integrity protection mechanisms are implemented, then security is improved, but device complexity and cost increase making low-cost IoT devices unable to support them

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security implementation into two parts: lightweight security mechanisms embedded in low-cost IoT devices, and enhanced security features hosted on remote servers or cloud platforms. This allows IoT devices to maintain basic security capabilities without requiring complex local processing, while still benefiting from advanced encryption and protection mechanisms through centralized services.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components such as security gateways, edge servers, or cloud-based security services that act as mediators between IoT devices and the network. These intermediaries handle complex encryption, authentication, and data integrity verification, allowing low-cost devices to achieve high security levels without directly implementing complex mechanisms themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If standardized security protocols are used across all devices, then ease of operation is improved, but adaptability to different application requirements deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidadaptability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security configuration where security parameters, protocols, and mechanisms can be adjusted based on application requirements, device capabilities, and network conditions. Security profiles are assigned dynamically to different IoT devices and applications, allowing the system to adapt security settings without requiring manual reconfiguration or complex device-specific implementations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes security parameters such as encryption algorithms, key lengths, authentication methods, and data protection mechanisms based on the specific requirements of different applications and devices. By parameterizing security configurations, the system maintains standardized operational interfaces while adapting security characteristics to match diverse application needs.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11909724B2Application and network slice security profile mapping for secure tunneling
Publication Date: 2024.02.20 VERIZON PATENT & LICENSING INC
  • US11909724B2 patent drawing
  • US11909724B2 patent drawing
  • US11909724B2 patent drawing

AI summary

A network node residing in a mobile network identifies a first network slice of the mobile network for use by a first session between a first user equipment device (UE) and a first application hosted by a first hosting device. The network node obtains a first security profile based on an identity of the first application and based on the identified first network slice, and establishes, using the obtained first security profile, a first secure tunnel between the network node and the first hosting device for transporting first data units associated with the first session between the network node and the first hosting device.