Trust Domain Identifier in Control Plane Messages

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional telecommunications networks face challenges in effectively communicating between different trust or security domains, particularly in roaming situations, due to the complexity of implementing multiple trust domains and the layered approach to security, which impedes efficient communication between network elements in different trust or security domains.

Innovation Solution

A method where control plane communication messages between network entities include trust or security domain information, allowing network entities to be aware of the trust or security domain properties, enabling communication to be shaped based on the existing trust or security domain situation, by transmitting and verifying specific trust or security domain information between entities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple trust domains are implemented in a telecommunications network, then security and trust management between different operators and network functions are improved, but device complexity and difficulty of operation increase

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A trust domain identifier is introduced as an intermediary element in control plane communication messages. This identifier acts as a mediator that enables network entities to recognize and verify trust domain boundaries without requiring complex security protocols at every communication point. The trust domain identifier is embedded in messages to facilitate automated trust verification between network entities across different trust domains.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameter of trust domain identification from implicit to explicit by adding a trust domain identifier parameter to control plane communication messages. This allows network entities to dynamically determine which trust domain a message originates from and apply appropriate security policies, simplifying the management of multiple trust domains compared to hard-coded security configurations.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If a layered approach to security is applied, then security structure is improved, but communication efficiency between network elements in different trust domains deteriorates

Engineering Contradiction:
Improvesecurity structureVSAvoidcommunication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Trust domain identification is performed preliminarily by including the trust domain identifier in the control plane communication messages themselves. This allows network entities to determine trust domain boundaries at the point of communication rather than requiring preliminary security handshakes or layered protocol negotiations, thereby maintaining communication efficiency while preserving security structure.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If trust domain information is included in control plane communication messages, then communication between different trust domains is improved, but message complexity increases

Engineering Contradiction:
ImprovecommunicationVSAvoidmessage complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The trust domain identification function is segmented from complex security protocols and embedded as a separate, standardized identifier field in control plane communication messages. This segmentation allows the trust domain information to be handled independently through simple matching and verification logic, reducing the overall complexity compared to integrated security protocols while improving ease of operation between trust domains.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP4456478A1Method for operating a user equipment with a telecommunications network and/or for communicating between or for operating at least two of a plurality of network functions or services of the telecommunications network or of a further telecommunications network, user equipment, system or telecommunications network, network entity being used as a first or second specific network entity, program and computer program product
Publication Date: 2024.10.30 DEUTSCHE TELEKOM AG
  • EP4456478A1 patent drawingFigure 1~2
  • EP4456478A1 patent drawingFigure 3~4
  • EP4456478A1 patent drawingFigure 5~7

AI summary

The invention relates to a method for operating a user equipment with a telecommunications network and/or for communicating between or for operating at least two of a plurality of network functions or services of the telecommunications network or of a further telecommunications network, wherein control plane communication messages - exchanged between such different network entities of or connected to the telecommunications network or of or connected to the further telecommunications network - comprise a trust or security domain information, wherein the telecommunications network and/or the further telecommunications network comprises or realizes at least a first and a second trust or security domain by means of -- a first subset of the network entities, this first subset being associated or assigned to the first trust or security domain, and by means of -- a second subset of the network entities, this second subset being associated or assigned to the second trust or security domain, wherein in case of a first specific network entity transmitting a specific control plane communication message to a second specific network entity, the method comprises the following steps: -- in a first step, the specific control plane communication message is transmitted, by the first specific network entity, wherein the control plane communication message comprises a specific trust or security domain information, the specific trust or security domain information being related to the specific trust or security domain to which the first specific network entity is associated or assigned, -- in a second step, the specific control plane communication message is received, by the second specific network entity, wherein the specific trust or security domain information is verified by the second specific network entity.