Self-healing slicing system based on cyberhealth score for 5G network slicing.

TR202613152A2Pending Publication Date: 2026-09-21TURK TELEKOMUNIKASYON A S
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
TR202613152
Authority / Receiving Office
TR · TR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2026-08-04
Publication Date
2026-09-21

Smart Images

  • Figure 00000006_0000
    Figure 00000006_0000
Patent Text Reader

Abstract

The invention is a self-improving slice system for 5G network slicing based on cyberhealth scores. Thanks to the Cyber ​​Security Status Monitoring Module (1) deployed in the 5G core network, edge, and cloud environments, the threat surface, anomaly behaviors, and attack indicators of the infrastructure on which each 5G slice operates are continuously monitored in real-time and converted into normalized security status records. The collected security telemetry is evaluated by the Dynamic Risk Analysis and Decision Engine (2), which calculates an instantaneous attack probability and risk score for each slice. This engine not only detects attacks but also generates proactive security decisions on whether the slice should continue operating in the current environment if the risk level approaches critical thresholds. When the risk level exceeds the defined threshold, the Seamless Secure Migration Orchestrator (3) is activated for the relevant slice.Instead of leaving the slice in a passive state, the orchestrator initiates a migration process to a more secure infrastructure area, maintaining service continuity during this migration. The migration process is managed by the Identity and Traffic Continuity Protection Layer (4). This layer protects the slice's IP identity, prevents active sessions from being interrupted, and transparently routes user traffic to the new environment, thus avoiding any service interruptions or reconnections. In the final stage, all slice deployment and secure operation processes are carried out on the Attack-Isolated Secure Operating Area (5). Thus, when a cyberattack occurs, there are no active slices on the affected systems; 5G services continue uninterrupted, independent of the attack, in an isolated and secure manner.
Need to check novelty before this filing date? Find Prior Art

Description

1 TARIFF Self-healing slicing system based on cyberhealth score for 5G network slicing. Technical Area 5 The invention has implications for 5G telecommunications networks, network slicing, cybersecurity, autonomous network management, and artificial intelligence. Intelligence-based traffic routing and service migration between data center / edge platforms. Used in various fields, self-improving according to cyberhealth score for 5G network slicing. It is related to the slicing system. State of the Art Today, 5G network slicing architecture slices encompass QoS, throughput, latency, and bandwidth. It distributes slices according to performance parameters such as those mentioned. However, the slices are distributed according to the data they are linked to. The central or edge platform is unaware of the cyberattack threat level. A data when the target is subjected to a DDoS / ransomware / exploit / APT attack or 15 When security systems like firewalls / IDS / IPS weaken, Slice reacts to this situation; that is The problem becomes apparent after the attack begins. The following are shortcomings in current slice architectures. It is located at: The slices continue to run on the DC or edge under attack. No slice evaluates the security risk level of the platform it runs on. 20 There is no preventative migration mechanism in place to anticipate cyberattacks. There is no security-based automatic location switching between 5G core, data center, and edge. Security logs and telemetry data located in data centers are processed by network slicing. It is not in use. Due to this deficiency, instead of mitigating the impact of the attack, the slices were used in the 25 days the attack occurred. The platform remaining static results in interruptions, service disruptions, or delays. 5G service While its dynamism is sensitive to performance as well as cybersecurity, In the current architecture, the slices are positioned in a passive and vulnerable way against attacks. Due to the negative aspects described above and the current solutions regarding the issue... Due to its inadequacy, it has become necessary to make improvements in the relevant technical field. 30 In conclusion, a system that provides a solution to meet the needs described above. It has been improved. Purpose of the Invention The invention was created by drawing inspiration from existing situations and addressing the aforementioned drawbacks. 35 It aims to solve the problem. 2 The main purpose of the invention is to address 5G telecommunications networks, network slicing, cybersecurity, and autonomous networks. management, AI-based traffic routing, and services between data center / edge platforms. Cyberhealth score for 5G network slicing, usable in migration areas. The goal is to provide a self-healing slice system. Another purpose of the invention is to enable data processing in Türk Telekom's 5G infrastructure, where each slice operates. depending on the security status, attack risk, and system health of the central or edge platform The goal is to enable it to automatically heal itself and move to the safest position. Another aim of the invention is to segment the data based on cyber parameters, rather than delay / performance parameters. By directing it according to the level of resistance, neutralize the effect of the attack before it happens. The goal is to eliminate; assigning a “Cyber ​​Resilience Score” to each 5G slot and 10 The goal is to enable the slices to migrate themselves based on this score; each DC / edge / slice the combination of the risk of constant AI attacks, firewall / IDS stability, The aim is to enable analysis of abnormal traffic density and system telemetry; The goal is to calculate a slice-specific security resilience score (0–100) from the data; the score If it falls below a certain threshold, slice will automatically leave its current location and that 15 The goal is to move the network to the most secure platform with the highest score; the migration process The goal is to ensure that slicing is performed without service interruption via the control plane; The goal is to store every score change and slice migration on the blockchain; Even if an attack occurs in the region, the segments in that region will autonomously operate without delay. The goal is to ensure a secure transition; the 5G network is not waiting for an attack, but rather preparing for an attack. to transform into an adaptive immune system that reorganizes itself in anticipation of such a possibility to provide. The structural and characteristic features and all the advantages of the invention are given in the figure below. Thanks to the detailed explanation written with references to the diagram, it becomes clearer. It will be understood. 25 Figures that will help understand the invention. Figure 1 shows the general architecture of the system that is the subject of the invention. Description of Part References 30 1. Cybersecurity Status Monitoring Module 2. Dynamic Risk Analysis and Decision Engine 3. Seamless Safe Migration Orchestra 4. Identity and Traffic Continuity Protection Layer 5. Attack-Isolated Secure Workspace 35 3 Detailed Description of the Invention This detailed explanation describes the cyberhealth score for 5G network slicing, which is the subject of the invention. The self-healing slice system preferred structures, not only better at the subject It is explained in order to facilitate understanding. 5 The invention is a slicing system for 5G network slicing that improves itself based on a cyberhealth score. Cybersecurity posture deployed in 5G core network, edge and cloud environments. Thanks to the Monitoring Module (1), the infrastructure on which each 5G slice operates can be monitored for threats. The surface, anomalous behavior, and attack indicators are continuously monitored in real time, and They are converted into normalized security status records. 10 The collected security telemetry is processed by Dynamic Risk Analysis and Decision Engine (2). By evaluating each slice, an instantaneous attack probability and risk score are calculated. This engine, It not only detects attacks; it also warns when the risk level approaches critical thresholds. in this case, whether slice should continue to work in the current environment It makes proactive security decisions. 15 When the risk level exceeds the defined threshold, the Seamless Safe Migration Orchestra (3) is activated for the relevant slice. It comes into play. Instead of leaving the slice in a passive state, the orchestrator chooses a safer approach. It initiates the migration process to a designated infrastructure area and provides service during this migration process. It maintains its continuity. The migration process is managed by the Identity and Traffic Continuity Protection Layer (4). This layer 20 This ensures that Slice's IP address is protected, active sessions are not interrupted, and user traffic remains uninterrupted. The system is transparently redirected to the new environment; thus, there will be no interruption or re-service. No connection is needed. In the final stage, all slice positioning and secure execution processes are Attack Isolated. It is maintained on the Secure Working Area (5). Thus, when a cyber attack occurs, 25 No active slices are found in affected systems; 5G services are independent of the attack, isolated, and It continues safely and uninterrupted. The components and their functions used in the system are as follows: Cyber ​​Security Status Monitoring Module (1), security logs on DC / edge, IDS / IPS It continuously collects data and anomaly indicators. 30 Dynamic Risk Analysis and Decision Engine (2) uses collected telemetry to analyze the attack for each slice. It creates a stamina score. Continuous Secure Migration Orchestra (3), security score reduction segment without service interruption It moves to the most secure DC / edge platform. Identity and Traffic Continuity Protection Layer (4) protects each slice migration and security history 35 It stores the information immutably on the blockchain. 4 Attack-Isolated Secure Workspace (5), delay on the new platform after migration and It optimizes capacity balance. The system performs the following functions: Cybersecurity telemetry (IDS / IPS logs, attack signatures, firewall signals, anomalies) (indicators) continuously collected from data center and edge platforms, 5 The collected telemetry is analyzed by artificial intelligence to determine cybersecurity for each 5G segment. Calculation of endurance / risk score, When the security resilience score falls below the defined threshold, the segment becomes a risky platform. The Autonomous Migration Manager needs to be triggered to leave. Automatic transfer of slices to the safest DC / edge platform without causing service interruption and 10 smooth redirection of traffic flow, Immutable records of migration processes and security resilience history on the blockchain. Storing it in this format and optimizing capacity / performance on the new platform.

Claims

REQUESTS 1.5G network slicing is a slicing system that improves itself based on a cyberhealth score, feature; In the 5G core network, each 5G slice is positioned in edge and cloud environments. The threat surface, anomaly behaviors, and attack indicators of the infrastructure he is working on are 5 real-time continuous monitoring and normalized security status records Transforming Cyber ​​Security Status Monitoring Module (1), By evaluating the collected security telemetry, the probability and risk of a real-time attack are determined for each slice. The score is calculated, and if the risk level approaches critical thresholds, the slice's current status is adjusted. 10 that generate proactive safety decisions about whether or not to continue working in the environment Dynamic Risk Analysis and Decision Engine (2), When the risk level exceeds the defined threshold, the system activates for the relevant slice, leaving the slice in a passive state. instead of delaying, it initiated the process of transitioning to an infrastructure area marked as more secure. And the Continuous Secure Migration Orchestra, which maintains service continuity throughout this migration process. (3), 15 It manages the migration process, protects the IP address of the slice, and prevents active sessions from being interrupted. by blocking and transparently redirecting user traffic to the new environment, thereby preventing any disruption to the service. Identity and Traffic Continuity prevents the need for an interruption or reconnection. Protective Layer (4), all slice positioning and secure execution processes are carried out on cyber 20 5G prevents active slicing on affected systems at the moment the attack occurs. ensuring that services continue uninterrupted in an independent, isolated and secure manner, free from attacks. Provides an Attack-Isolated Secure Workspace (5) It includes.

2. The system compliant with System 1, its features include; security logs on the DC / edge, IDS / IPS data 25 and the Cyber ​​Security Status Monitoring Module (1) which continuously collects anomaly indicators It includes.

3. This system complies with Request 1 and its feature is that it uses the collected telemetry to perform an attack for each slice. It includes Dynamic Risk Analysis and Decision Engine (2) which generates a resilience score.

4. The system complies with Request 1, and its feature is that the security score decreases by 30 without service interruption. It includes the Seamless Secure Migration Orchestrator (3) which carries you to the most secure DC / edge platform.

5. The system complies with Request 1, and its characteristic is that the migration and security history of each segment cannot be altered. Identity and Traffic Continuity Protection Layer (4) which stores on the blockchain. It includes.

6. The system compliant with Request 1, its feature is; delay and capacity 35 on the new platform after migration. It includes an Attack-Isolated Secure Workspace (5) which optimizes its balance.