URSP Integrity Protection Across Visited 5G Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G communication networks, there is a lack of mechanisms to prevent Visited Public Land Mobile Networks (VPLMNs) from modifying User Equipment Route Selection Policy (URSP) rules sent by Home Public Land Mobile Networks (HPLMNs, leading to unauthorized changes in traffic routing and potential security breaches.

Innovation Solution

Implementing a secure URSP support indicator and integrity protection using Message Authentication Codes (MAC-I) to ensure that URSP rules are not tampered with during transmission from the HPLMN to the UE, ensuring the integrity and confidentiality of the policy data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If URSP data is transmitted from HPLMN to VPLMN without integrity protection, then transmission simplicity is maintained, but security and reliability deteriorate due to unauthorized modification risks

Engineering Contradiction:
Improveintegrity of URSP dataVSAvoidsecurity procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by performing integrity protection on URSP data before transmission from HPLMN to VPLMN. The home network generates and attaches integrity protection information (such as MAC-I or digital signature) to the URSP data in advance, ensuring that the data cannot be tampered with during transmission through the visited network. This pre-protection mechanism resolves the contradiction by establishing reliability before the security threat materializes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism in the form of integrity protection information that mediates between the HPLMN and VPLMN/UE. This intermediary element (integrity check value, signature, or MAC) acts as a trusted intermediary that verifies the authenticity and integrity of URSP data without requiring complex trust relationships between all network elements. The intermediary resolves the contradiction by providing a standardized security layer that maintains reliability while managing complexity through established cryptographic protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If integrity protection is applied to URSP data, then security against unauthorized modification is improved, but processing overhead and complexity increase

Engineering Contradiction:
Improveprotection against unauthorized modificationVSAvoidsecurity processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by utilizing established cryptographic parameters and algorithms for integrity protection (such as AES-based MAC, HMAC, or digital signatures using ECC/RSA). By standardizing these cryptographic parameters across the network, the complexity of security processing is managed through parameter specification rather than algorithmic complexity. This resolves the contradiction by providing strong protection against unauthorized modification while keeping implementation complexity manageable through standardized parameters.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements self-service through automated integrity verification at the UE and network elements. The UE automatically verifies the integrity protection information attached to URSP data without requiring manual intervention or complex decision-making processes. Network elements self-verify the authenticity of received URSP data using the attached integrity information, resolving the contradiction by making security processing transparent and automated, thereby reducing perceived complexity while maintaining strong protection.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If URSP data is sent through VPLMN without security protection, then network roaming functionality is maintained, but security threats from data tampering increase

Engineering Contradiction:
Improveroaming capabilityVSAvoidunauthorized modification of URSP data
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by pre-countering the potential harm of unauthorized modification through integrity protection. Before the URSP data traverses the VPLMN where tampering could occur, the HPLMN attaches integrity protection information that proactively prevents successful tampering. This preliminary anti-action resolves the contradiction by maintaining roaming functionality through the VPLMN while pre-neutralizing the security threat of data tampering.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent converts the potential harm of transmitting sensitive URSP data through untrusted VPLMN into a benefit by using the transmission opportunity to demonstrate and enforce security measures. The very act of sending data through the VPLMN becomes an opportunity to verify the integrity protection mechanism, ensuring that only authenticated and unmodified data reaches the UE. This resolves the contradiction by transforming the security risk of roaming transmission into a verified security demonstration.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentEP4346258B1Secure user equipment policy data in a communication network environment
Publication Date: 2026.05.20 NOKIA TECHNOLOGIES OY
  • EP4346258B1 patent drawingFigure 1
  • EP4346258B1 patent drawingFigure 2
  • EP4346258B1 patent drawingFigure 3

AI summary

Techniques for managing user equipment policy data in a communication network environment are disclosed. For example, techniques are provided for managing user equipment policy data to be sent to user equipment by protecting the user equipment policy data in a communication network to which the user equipment is subscribed (e.g., a home communication network) such that the user equipment policy data can be sent to the user equipment through a communication network to which the user equipment is attached (e.g., a visited communication network) in a secure manner.