User Equipment Control Plane Authorization for Secure Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional telecommunications networks limit flexibility and security in configuring user equipment parameters, as only the home network can modify critical parameters, while non-critical parameters can be changed by the visited network or user with weak or no authentication, restricting desirable configurations and potentially compromising security.

Innovation Solution

Implementing a control plane functionality that allows user equipment to receive authorization information and process requests from external network nodes, using OAuth principles for delegated authorization, enabling third-party authorization, conditional access, and secure configuration modifications through a control plane channel.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If only the home network can modify critical parameters of user equipment, then security is maintained, but flexibility and adaptability are restricted

Engineering Contradiction:
ImprovesecurityVSAvoidflexibility in configuration
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the authorization mechanism by introducing an authorization token system that divides the traditional home-network-only control into multiple authorized entities. The home network retains control by issuing tokens, while other networks can modify parameters when presented with valid tokens, thus segmenting the authorization function while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authorization token acts as an intermediary that mediates between the home network and external networks. Instead of direct control, the home network issues tokens that serve as intermediaries, allowing external networks to modify parameters securely without direct access, thus resolving the contradiction between security and flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If visited network or user can change non-critical parameters with weak or no authentication, then flexibility is improved, but security is compromised

Engineering Contradiction:
Improveconfiguration flexibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary action by requiring authorization tokens to be obtained before parameter modification. External networks must first acquire valid tokens from the home network, establishing authorization in advance. This preliminary authorization step ensures that while flexibility is maintained through multiple potential authors, security is preserved through pre-validated credentials.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If control plane functionality is implemented with authorization tokens, then security and flexibility are enhanced, but device complexity increases

Engineering Contradiction:
ImproveflexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements feedback mechanisms where the user equipment validates authorization tokens received from external networks against the home network's authorization data. This feedback loop ensures that only properly authorized modifications are accepted, maintaining security and flexibility while managing complexity through structured validation procedures.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240349045A1Operation of a user equipment within or as part of a telecommunications network using a control plane functionality
Publication Date: 2024.10.17 DEUTSCHE TELEKOM AG
  • US20240349045A1 patent drawing

AI summary

A method for operating or for modifying the operation of a user equipment within or as part of a telecommunications network includes the following steps: in a first step, the user equipment receives, from an authorization functionality, at least one piece of authorization information, and the user equipment receives, from a requesting entity or a requesting network node, an authorization request message; and in a second step, the user equipment determines whether the authorization request is valid, and based on the authorization request being valid, processes the received authorization request message according to its content.