User Plane Security Policy Determination for Relay Sessions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for determining user plane security enforcement information in device-to-device communication, particularly when a remote device is outside network coverage or has poor communication quality, fail to adequately satisfy security requirements for data transmission.

Innovation Solution

A method involving a session management network element that receives a request indicating a relay-type session, determines user plane security enforcement information based on subscription information or preconfigured policies, and configures security activation status between a terminal device and an access network device, ensuring security requirements are met.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If user plane security enforcement information is determined based only on subscription information or preconfigured information of the relay device, then the determination process is simple, but the security requirement of transmitted data of the remote device cannot be satisfied

Engineering Contradiction:
Improvesecurity requirement of transmitted dataVSAvoidsecurity enforcement information determination process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security enforcement information determination into multiple components: relay device subscription information, remote device subscription information, and user plane security policies. This segmentation allows comprehensive security coverage while maintaining clear responsibility boundaries and manageable complexity in each segment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies preliminary action by obtaining subscription information and user plane security policies in advance during session establishment, before actual data transmission begins. This ensures security requirements are pre-configured and enforced from the outset, avoiding complex real-time security assessments during data transmission.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If comprehensive security policies for both relay and remote devices are implemented, then security requirement is satisfied, but the determination process becomes complex

Engineering Contradiction:
Improvesecurity requirement of transmitted dataVSAvoidsecurity enforcement information determination
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The session management network element acts as an intermediary that automatically collects subscription information from both relay and remote devices, retrieves user plane security policies, and determines the final security enforcement information. This intermediary approach shields operators from complex manual security configuration while ensuring comprehensive security coverage.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameter of security enforcement determination from static (relay-only) to dynamic (relay + remote device information). By incorporating multiple parameters including both devices' subscription information and security policies, the system adapts security enforcement to the specific characteristics of each communication scenario.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12513527B2User plane security enforcement information determining method, apparatus, and system
Publication Date: 2025.12.30 HUAWEI TECH CO LTD
  • US12513527B2 patent drawing
  • US12513527B2 patent drawing
  • US12513527B2 patent drawing

AI summary

A user plane security enforcement information determining method and an apparatus are provided, to ensure a security requirement of transmitted data of a remote device. In this application, a session management network element may receive a first request for creating a relay-type session of a first terminal device. Then, the session management network element determines first user plane security enforcement information of the session based on first information, and sends the first user plane security enforcement information of the session to an access network device, where the first user plane security enforcement information of the session is for determining a first user plane security activation status of the session between the first terminal device and the access network device.