Visited Session Management Device Roaming Security Policy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G mobile communications networks, ensuring secure data transmission during network roaming between different public land mobile networks (PLMN) is a challenge, as existing methods lack effective mechanisms to protect data integrity and confidentiality across different network elements.

Innovation Solution

A network roaming protection method that involves a visited session management device processing a security requirement set from user equipment (UE) and a home network's security requirements to generate a target security policy, which is used to derive a target shared key for secure end-to-end data transmission between the UE and the visited gateway, ensuring compatibility with security requirements of both home and visited network elements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network roaming is enabled between different PLMNs, then user equipment can access services in visited networks, but data transmission security between UE and network elements cannot be ensured

Engineering Contradiction:
Improvenetwork roaming capabilityVSAvoiddata transmission security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a security policy control function as an intermediary component that mediates between the home network and visited network. This function collects security requirements from both networks and generates a unified security policy, acting as a mediator that reconciles different security requirements and enables secure roaming without requiring direct trust between heterogeneous network elements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security policy is segmented into multiple components: home network security requirements, visited network security requirements, and a generated security policy that combines both. The key management is also segmented by separating the base key (from home network) from the derived session keys (for specific services and network elements). This segmentation allows independent optimization of security for each network while maintaining overall consistency.

Inventive Principle:
Principle #1Segmentation

2Reliability

If security policies are tailored for each network element, then data protection is enhanced, but policy complexity and management overhead increase

Engineering Contradiction:
Improvedata protectionVSAvoidsecurity policy complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple security requirements (home network and visited network) into a single unified security policy. Instead of managing separate security policies for each network element, the system combines all requirements and generates one comprehensive policy that applies to the entire roaming session, reducing management complexity while maintaining thorough protection.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security policy is generated in advance during the session establishment phase, before actual data transmission begins. The security policy control function proactively collects security requirements from both networks and derives the appropriate keys and policies beforehand, eliminating the need for real-time security negotiations and reducing operational complexity during data transmission.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11109230B2Network roaming protection method, related device, and system
Publication Date: 2021.08.31 HUAWEI TECH CO LTD
  • US11109230B2 patent drawing
  • US11109230B2 patent drawing
  • US11109230B2 patent drawing

AI summary

Embodiments of the present disclosure disclose a network roaming protection method and related device. The method includes: receiving, by a visited session management device, a first session establishment request that includes a first security requirement; obtaining, by the visited session management device, a target security policy, where the target security policy is obtained by processing the first security requirement set and a second security requirement set using a preset rule; and sending the target security policy to the UE instructing the UE to generate a target shared key based on a reference shared key and according to a rule defined by the target security policy, where the target shared key is used to protect secure end-to-end data transmission between the UE and the visited gateway.