URSP Rule Digital Certificate Application Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current UE Route Selection Policies (URSP) rules lack secure identification mechanisms, allowing malicious applications to impersonate legitimate ones and misuse data connection settings, leading to potential security breaches and unauthorized data transmission.

Innovation Solution

Extending the traffic descriptor component of URSP rules to include digital certificate information, such as certificate fingerprints, ensuring that only applications signed with matching digital certificates can apply the corresponding data connection parameters for transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital certificate information is added to URSP rules to enhance security, then application authentication capability is improved, but rule complexity increases

Engineering Contradiction:
Improveapplication authentication capabilityVSAvoidrule complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the URSP rule structure by separating the traffic descriptor component (which now includes digital certificate information) from the route selection descriptor component. This segmentation allows digital certificates to be integrated without fundamentally restructuring the entire rule system, thereby enhancing authentication capability while limiting the increase in overall complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces digital certificate information as an intermediary element within the traffic descriptor component. This intermediary serves as a mediator between the application identity and the route selection parameters, enabling secure authentication without requiring direct complex interactions between all rule components.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If digital certificate verification is implemented in URSP rules, then data transmission security is improved, but processing overhead increases

Engineering Contradiction:
Improvedata transmission securityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by incorporating digital certificate information into the URSP rules in advance, before data transmission occurs. The certificate verification is performed as part of the rule matching process rather than as a separate post-processing step, which reduces overall processing overhead by combining authentication with existing rule evaluation operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240056313A1Selecting a data connection based on digital certificate information
Publication Date: 2024.02.15 LENOVO (SINGAPORE) PTE LTD
  • US20240056313A1 patent drawing
  • US20240056313A1 patent drawing
  • US20240056313A1 patent drawing

AI summary

Apparatuses, methods, and systems are disclosed for selecting a data connection based on digital certificate information. One apparatus includes a transceiver and a processor that receives a request to send a data packet and determines a first application identity used by a first application. The processor finds a first policy rule in the apparatus that matches the first application identity and determines whether the first application matches a digital certificate information. Here, the first policy rule contains the digital certificate information. Upon determining that the first application matches the digital certificate information, the processor applies the first policy rule to select a first set of data connection parameters and the transceiver transmits the data packet via a data connection using the first set of data connection parameters.