URSP Rule Digital Certificate Application Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current UE Route Selection Policies (URSP) rules lack secure identification mechanisms, allowing malicious applications to impersonate legitimate ones and misuse data connection settings, leading to potential security breaches and unauthorized data transmission.
Innovation Solution
Extending the traffic descriptor component of URSP rules to include digital certificate information, such as certificate fingerprints, ensuring that only applications signed with matching digital certificates can apply the corresponding data connection parameters for transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If digital certificate information is added to URSP rules to enhance security, then application authentication capability is improved, but rule complexity increases
Solution Approach 1:
The patent segments the URSP rule structure by separating the traffic descriptor component (which now includes digital certificate information) from the route selection descriptor component. This segmentation allows digital certificates to be integrated without fundamentally restructuring the entire rule system, thereby enhancing authentication capability while limiting the increase in overall complexity.
Solution Approach 2:
The patent introduces digital certificate information as an intermediary element within the traffic descriptor component. This intermediary serves as a mediator between the application identity and the route selection parameters, enabling secure authentication without requiring direct complex interactions between all rule components.
2Reliability
If digital certificate verification is implemented in URSP rules, then data transmission security is improved, but processing overhead increases
Solution Approach 1:
The patent implements preliminary action by incorporating digital certificate information into the URSP rules in advance, before data transmission occurs. The certificate verification is performed as part of the rule matching process rather than as a separate post-processing step, which reduces overall processing overhead by combining authentication with existing rule evaluation operations.
Data Source
AI summary
Apparatuses, methods, and systems are disclosed for selecting a data connection based on digital certificate information. One apparatus includes a transceiver and a processor that receives a request to send a data packet and determines a first application identity used by a first application. The processor finds a first policy rule in the apparatus that matches the first application identity and determines whether the first application matches a digital certificate information. Here, the first policy rule contains the digital certificate information. Upon determining that the first application matches the digital certificate information, the processor applies the first policy rule to select a first set of data connection parameters and the transceiver transmits the data packet via a data connection using the first set of data connection parameters.


