Network slice security management system and method thereof

The network slice security management system addresses the spread of malware across terminals by isolating infected devices to a quarantine network slice, ensuring network and terminal protection with uninterrupted service through customized security policies and agents.

WO2025211550A1PCT designated stage Publication Date: 2025-10-09NETCUBE INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2025/001083
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-04
Filing Date
2025-01-20
Publication Date
2025-10-09

AI Technical Summary

Technical Problem

In mobile communication systems providing network slicing services, a security breach in one terminal can spread malware to other terminals, potentially affecting the entire network, necessitating effective security management to protect both the network and terminals.

Method used

A network slice security management system that includes a security agent to check for terminal security breaches, defines security policies, and determines whether to connect terminals to normal or quarantine network slices based on security status, allowing for isolation and resolution of security issues without service interruption.

Benefits of technology

The system effectively isolates infected terminals to a quarantine network slice, protecting the normal network and other terminals while maintaining continuous network slice service by utilizing network slicing technology.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2025001083_09102025_PF_FP_ABST
    Figure KR2025001083_09102025_PF_FP_ABST
Patent Text Reader

Abstract

A network slice security management system according to an embodiment of the present invention comprises: a security agent providing unit for installing, on a user terminal, a security agent inspecting security breaches in the user terminal or updating the security agent; a security policy setting unit for defining guidelines and rules required for the security agent; and a network slice policy management unit for receiving the security status of the terminal provided by a network slice agent, installed on the user terminal, on the basis of the results of the inspection of security breaches by the security agent, and determining, on the basis of the terminal security status, whether to connect the user terminal to a normal network slice or a quarantine network slice, wherein the quarantine network slice is a network slice for accessing a quarantine data network for isolating the user terminal when there is a security problem in the user terminal.
Need to check novelty before this filing date? Find Prior Art

Description

Network Slice Security Management System and Method Thereof

[0001] The present invention relates to a network slice security management system and method thereof. More specifically, the present invention relates to a system and method for protecting a network and terminals when a security issue occurs in a mobile communication system that provides network slicing services to multiple terminals.

[0002] Network slicing is a technology that divides a single physical network infrastructure into multiple virtual networks. Each network slice can be customized to meet specific service requirements or can more efficiently allocate and utilize network resources, helping to increase agility and reduce operating costs.

[0003] To facilitate the utilization of such network slicing, a network slice onboarding system may be provided that performs network slice subscription application and authorization verification for 5G users and performs integrated provisioning.

[0004] FIG. 1 is a diagram illustrating a network slicing onboarding system to which the present invention can be applied.

[0005] A user terminal (10) can perform wireless communication and use a network slice service through a mobile communication network (20). The mobile communication network (20) can include a base station, gNB (21), and network function units, such as AUSF (22), PCF (23), SMF (24), AMF (25), and UPF (26).

[0006] gNB (Next Generation Node B) (21) may refer to a base station, an access point (AP), a radio access station (RAS), a base transceiver station (BTS), a mobile multihop relay (MMR)-BS, etc., and may include all or part of the functions of an access point, a radio access station, a node B, a base transceiver station, an MMR-BS, etc.

[0007] The AUSF (Authentication Server Function) (22) performs authentication of a user terminal using subscriber authentication data, the AMF (Access and Mobility Function) (25) supports mobility using subscriber authentication data, the PCF (Policy Control Function) (23) determines policies regarding the mobility and session management, the SMF (Session Management Function) (24) manages session maintenance / release for multiple connection sessions, and the UPF (User Plane function) (26) transfers packets transmitted from a user terminal to a data network.

[0008] The network slicing onboarding system (40) provides a network slice-only app (11), a network slice agent (12), and a network slice profile to a user terminal (10), thereby performing onboarding to the network slice system (30) and supporting the user terminal (10) to quickly use the network slice.

[0009] Specifically, the network slice agent (12) decodes or decrypts information of a network slice profile created and set by the network slicing onboarding system (40) and provides the information to enable the use of 5G network slice services in the mobile communication network. The network slice agent (12) supports the flow of network slice-based dedicated network application data by using the received network slice profile until the network slice profile is updated.

[0010] These network slicing systems, which provide fast and stable network connections, are primarily built and operated by mobile carriers, but recently, there has been an increase in cases where various organizations and companies are independently building and operating private 5G systems.

[0011] Here, the network of an organization or company is simultaneously accessed by multiple users' terminals. If one terminal is infected with malware, and multiple terminals are connected within the network slice, and the malware can spread, there is a possibility that the infected terminal can spread the malware to other terminals. As a result, the entire 5G system or network connected to the 5G system could be adversely affected.

[0012] Therefore, when a security breach occurs, such as a single terminal connected to a network slice being infected with malware, appropriate security measures and management are required to maintain the safety of the entire network.

[0013] The technical problem to be solved by the present invention is to provide a security management system and method for protecting a network and terminals when a security problem occurs in a mobile communication system that provides network slicing services to multiple terminals in network slice security management.

[0014] In addition, the present invention has as a technical task a security management system and method for protecting a network and a terminal by effectively utilizing network slicing technology together with a network slicing onboarding system to which the present invention is applicable.

[0015] In order to achieve the above technical task, a network slice security management system according to an embodiment of the present invention includes a security agent providing unit that installs or updates a security agent that checks for terminal security infringement in a user terminal; a security policy setting unit that defines guidelines and rules required for the security agent; and a network slice policy management unit that receives a terminal security status provided by a network slice agent installed in the user terminal based on a security infringement check result of the security agent, and determines whether to connect the user terminal to a normal network slice or a quarantine network slice based on the terminal security status; wherein the quarantine network slice is a network slice for connecting to a quarantine data network for isolating the user terminal when there is a security problem in the user terminal.

[0016] In addition, when the network slice policy management unit receives a security breach status of the user terminal, it may request the mobile communication system to cancel permission for the normal network slice access, provide the quarantine network slice information received from the mobile communication system to the network slice agent, and cause the network slice agent to connect the user terminal to the quarantine network slice based on the quarantine network slice information.

[0017] In addition, when the user terminal is connected to the quarantine network slice, the network slice policy management unit may, upon receiving a terminal security good status, request permission to access the normal network slice from the mobile communication system, provide the normal network slice information provided from the mobile communication system to the network slice agent, and the network slice agent may connect the user terminal to the normal network slice based on the normal network slice information.

[0018] In addition, when the user terminal is first connected to or booted in the mobile communication system, the network slice agent may connect the user terminal to a quarantine network slice, and when the network slice policy management unit receives a good security status of the user terminal, the network slice policy management unit may request the mobile communication system to grant permission to connect to the normal network slice, and provide the normal network slice information provided from the mobile communication system to the network slice agent, and the network slice agent may connect the user terminal to the normal network slice based on the normal network slice information.

[0019] In addition, the network slice policy management unit may request the mobile communication system to create the quarantine network slice so as to simultaneously operate a normal data network connected to the normal network slice and a quarantine data network end-to-end separated therefrom.

[0020] In addition, the quarantine data network may further include a quarantine data network management unit for diagnosing security breaches of user terminals connected to the quarantine data network and managing and resolving security issues.

[0021] A network slice security management method according to an embodiment of the present invention comprises: a step of providing a security agent installed or updated in a user terminal by a network slice security management system for checking for a terminal security breach; a security policy setting step in which the network slice security management system defines guidelines and rules required for the security agent; and a network slice policy determination step in which the network slice security management system receives a terminal security status provided by the network slice agent installed in the user terminal based on a security breach check result of the security agent, and determines whether to connect the user terminal to a normal network slice or a quarantine network slice based on the terminal security status; wherein the quarantine network slice is a network slice for connecting to a quarantine data network for isolating the user terminal when there is a security problem with the user terminal.

[0022] In addition, the network slice policy decision step may, when receiving a security breach status of the user terminal, request the mobile communication system to cancel permission for access to the normal network slice, provide the quarantine network slice information provided from the mobile communication system to the network slice agent, and cause the network slice agent to connect the user terminal to the quarantine network slice based on the quarantine network slice information.

[0023] In addition, when the user terminal is connected to the quarantine network slice, the network slice policy management unit may, upon receiving a terminal security good status, request permission to access the normal network slice from the mobile communication system, provide the normal network slice information provided from the mobile communication system to the network slice agent, and the network slice agent may connect the user terminal to the normal network slice based on the normal network slice information.

[0024] In addition, when the user terminal is first connected to or booted in the mobile communication system, the network slice agent may connect the user terminal to a quarantine network slice, and the network slice policy determination step may, upon receiving a good security status of the user terminal, request the mobile communication system to grant permission to connect to the normal network slice, provide the normal network slice information provided from the mobile communication system to the network slice agent, and the network slice agent may connect the user terminal to the normal network slice based on the normal network slice information.

[0025] In addition, the network slice policy decision step may further include a step of requesting the mobile communication system to create the quarantine network slice so as to simultaneously operate a normal data network connected to the normal network slice and a quarantine data network end-to-end separated therefrom.

[0026] In addition, the network slice security management system may further include a quarantine data network management step for diagnosing a security breach situation of a user terminal connected to the quarantine data network and resolving and managing security issues.

[0027] A network slice security management system and method according to an embodiment of the present invention can protect a normal network and devices connected to the network by temporarily transferring a communication network of a user terminal that has suffered a security breach, such as infection by malware, to a quarantine network slice instead of a normal network slice by utilizing network slicing technology.

[0028] Additionally, according to an embodiment of the present invention, even if a security issue occurs, the user can use the network slice service without interruption.

[0029] In addition, according to an embodiment of the present invention, not only can a normal data network be protected by isolating a terminal in which a security issue has occurred, but also the network slice service can be normalized without service interruption by resolving the security issue of the terminal through a security agent or the like.

[0030] In addition, the network slice security management system according to an embodiment of the present invention requests the 5G system (50) to create and manage a network slice, manages information by setting a policy for each network slice, and provides each network slice information to the 5G system and a network slice agent to isolate the user terminal from the data network or normally connect the user terminal to the data network, thereby maintaining and managing the security of the terminal and the network slice service.

[0031] Meanwhile, the present invention can effectively utilize network slicing technology together with an applicable network slice onboarding system to efficiently manage network resources and fulfill user requirements.

[0032] Additionally, each network slice can have customized security policies tailored to its use cases and requirements.

[0033] Furthermore, security agents can be used to detect antivirus and intrusions, enabling monitoring and response to security threats within network slices.

[0034] The effects of the present invention are not limited to the effects described above, and should be understood to include all effects that can be inferred from the detailed description of the present invention or the composition of the invention described in the claims.

[0035] FIG. 1 is a diagram illustrating a network slicing onboarding system to which the present invention can be applied.

[0036] FIG. 2 is a schematic diagram showing a network slice security management system according to an embodiment of the present invention.

[0037] FIG. 3 is a block diagram showing the configuration of a network slice security management system according to an embodiment of the present invention.

[0038] FIG. 4 is a signal flow diagram of a network slice security management method according to an embodiment of the present invention in a terminal connected to a normal network slice.

[0039] FIG. 5 is a signal flow diagram of a network slice security management system and method according to an embodiment of the present invention in a terminal where a security issue has occurred.

[0040] FIG. 6 is a signal flow diagram of a network slice security management system and method according to an embodiment of the present invention when a user terminal first connects to or boots up a 5G system.

[0041] Hereinafter, the present invention will be described with reference to the attached drawings. However, the present invention can be implemented in various different forms and is therefore not limited to the embodiments described herein. In the drawings, irrelevant parts have been omitted for clarity of description, and similar parts have been designated with similar reference numerals throughout the specification.

[0042] Throughout the specification, when a part is said to be "connected (connected, contacted, or coupled)" to another part, this includes not only cases where it is "directly connected," but also cases where it is "indirectly connected" with another member in between. Furthermore, when a part is said to "include" a component, this does not mean that it excludes other components, but rather that it may include other components, unless otherwise specifically stated.

[0043] The terminology used herein is merely used to describe specific embodiments and is not intended to limit the present invention. The singular expression includes the plural expression unless the context clearly indicates otherwise. In this specification, it should be understood that the terms "comprises" or "has" indicate the presence of a feature, number, step, operation, component, part, or combination thereof described in the specification, but do not exclude in advance the possibility of the presence or addition of one or more other features, numbers, steps, operations, components, parts, or combinations thereof.

[0044] As used herein, the term "module" includes a unit composed of hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit. A module may be an integrally formed component, or a minimal unit or portion thereof that performs one or more functions. For example, a module may be composed of an application-specific integrated circuit (ASIC).

[0045] Hereinafter, embodiments of the present invention will be described in detail with reference to the attached drawings.

[0046] FIG. 2 is a schematic diagram showing a network slice security management system according to an embodiment of the present invention.

[0047] The network slice security management system (100) can provide a security agent (13) to a user terminal (10) so that the security agent (13) can be installed and updated on the user terminal (10).

[0048] In addition, the network slice security management system (100) manages a security policy for the user terminal (10) and can transmit and receive the security status and network slice information of the user terminal (10).

[0049] Meanwhile, the network slice security management system (100) determines the type of network slice to be connected based on the security status of the user terminal (10), and transmits this to the 5G system (50) to request or cancel access permission for the network slice.

[0050] The 5G system (50) can create a network slice or change and provide network slice information that enables the use of a network slice service by reflecting a request from the network slice security management system (100), thereby granting access rights to the corresponding user terminal (10) or canceling granted access rights.

[0051] The above network slice information may include service identification information of the network slice, service application information, service subscriber information, service subscription and authorization information, telecommunications carrier linkage policy information, NSSAI (Network Slice Selection Assistance Information) used for selecting and using the network slice, DNN (Data Network Name) that identifies the data network, a network slice profile ID fixedly or dynamically assigned to a specific network slice to be used by a user, or information regarding service QoS that specifies the quality and grade of the service.

[0052] Additionally, the network slice security management system (100) can transmit and receive information between the 5G system (50) and the network slice.

[0053] The user terminal (10) may include a network slice dedicated app (11) that provides a network slice service, a network slice agent (12) that helps connect the user terminal (10) to the network slice using information of the network slice, and a security agent (13) that can check the security breach status of the terminal and resolve security issues.

[0054] Here, the user terminal (10) is a variety of smart devices that can connect to a mobile communication network and may be equipped with a communication module and a display module.

[0055] The 5G system (50) is a mobile communication system that complies with the 5G communication standard. This is merely intended to illustrate one embodiment, and should be understood to also include a mobile communication system that complies with the 6G communication standard, the next-generation mobile communication network.

[0056] A normal network slice (51) refers to a network slice that is created and used normally according to the requirements of an organization or enterprise, etc. A normal network slice (51) may be composed of at least one PDU session.

[0057] A quarantine network slice (52) is a network slice for isolating a user terminal (10) in the event of a security issue with the user terminal (10). It may be composed of at least one PDU session.

[0058] That is, according to an embodiment of the present invention, the 5G system can provide at least two network slices simultaneously.

[0059] A data network (60) is an external or local network that provides Internet services or various online services, and a user terminal (10) can access one of the data networks through a network slice.

[0060] A normal data network (61) is an end-to-end data network composed of at least one user terminal (10) connected through a normal network slice (51), and a quarantine data network (62) is an end-to-end data network composed of at least one user terminal (10) connected through a quarantine network slice (52).

[0061] FIG. 3 is a block diagram showing the configuration of a network slice security management system according to an embodiment of the present invention.

[0062] The network slice security management system (100) may include a security policy setting unit (110), a security agent provision unit (120), a network slice policy management unit (130), or a quarantine data network management unit (140).

[0063] The security policy setting unit (110) sets the security policy by defining the guidelines and rules required for the security agent (13).

[0064] For example, the security policy setting section can define the security agent's (13) security breach inspection cycle (or frequency) of the user terminal (10), related security breach inspection software, a notification system that notifies the network slice agent of the terminal's security status when a security breach situation of the terminal is detected or the terminal's security status is good, a firewall, antivirus software, and sniffing and packet analysis tools.

[0065] Specifically, the guidelines and rules required for the security agent (13) may include antivirus and antimalware software to protect the terminal from malicious software, patch and update management to keep the operating system and applications up to date, endpoint security to encrypt data on the terminal, block unauthorized access, and prevent data leakage, network security management to protect the network itself and its components, a firewall to protect the internal network from external threats by filtering traffic to block unauthorized access, and an intrusion detection and prevention system (IDS / IPS) to detect and block suspicious activities or known attack patterns.

[0066] The security agent providing unit (120) can provide the security agent to the user terminal (10).

[0067] For example, a security agent (13) can be provided to a user terminal (10) through a network without physical access, with the consent of the user or in compliance with the policy of an organization or company.

[0068] If the security agent (13) is not installed, the security agent (13) can be installed on the user terminal (10), and if there is an update for the security agent (13), the security agent (13) can be updated on the user terminal (10).

[0069] The network slice policy management unit (130) receives the terminal security status from the network slice agent (12) installed in the user terminal (10) based on the security breach inspection result of the security agent (13), and determines whether to connect to a normal network slice (51) or a quarantine network slice (52) through the network slice agent.

[0070] The network slice policy management unit (130) is described in detail later with reference to the signal flow diagrams of FIGS. 4, 5, and 6.

[0071] The quarantine data network management unit (140) monitors the quarantine data network (62) that is isolated from the normal data network (61).

[0072] Specifically, the quarantine data network management unit (140) tracks and analyzes traffic, bandwidth usage, failure situations, etc., strengthens security to protect the system from external intrusions and internal threats, manages security issues such as regularly updating network software, and in the event of a security breach, requests the security agent (13) to resolve the terminal security issue.

[0073] That is, the present invention utilizes network slicing technology to temporarily transfer a communication network of a device that has suffered a security breach, such as infection by malware, to a quarantine network slice (52) instead of a normal network slice (51), thereby protecting a normal data network (61) and a user terminal (10) connected to the network.

[0074] To this end, the 5G system (50) can be requested to create the quarantine network slice, so that a normal data network (61) connected to a normal network slice and a quarantine data network (62) separated end-to-end from it can be temporarily operated simultaneously.

[0075] FIG. 4 is a signal flow diagram of a network slice security management method according to an embodiment of the present invention in a terminal connected to a normal network slice.

[0076] That is, FIG. 4 describes a security management method in a state where a user terminal (10) is already connected end-to-end to a normal data network (61) through a normal network slice (51), and assumes that a network slice agent (12) is installed in the user terminal (10).

[0077] In step (S110), the network slice security management system (100) installs a security agent (13) with a set security policy on the user terminal (10) or performs an update if an update is required after installation.

[0078] In step (S120), the security agent (13) periodically checks whether the user terminal (10) has a security breach and, if there is a security problem, notifies the network slice agent (12) of the terminal security breach status.

[0079] In step (S130), the network slice agent (12) provides the notified terminal security breach status to the network slice security management system (100).

[0080] In step (S140), when the network slice security management system (100) receives the terminal security breach status, it requests the 5G system (50) to cancel permission to access the normal network slice (51).

[0081] In step (S141), the network slice security management system (100) receives quarantine network slice (52) information from the 5G system (50).

[0082] In step (S142), the network slice security management system (100) provides the quarantine network slice information to the network slice agent (12) and requests the user terminal (10) to connect to the quarantine network slice (52).

[0083] In step (S150), the network slice agent (12) connects the user terminal (10) to the quarantine network slice (52) based on the quarantine network slice information, thereby isolating the user terminal (10) in which a security breach has occurred from the normal data network (61).

[0084] According to an embodiment of the present invention, a user terminal (10) that has suffered a security breach, such as infection by a malicious code, can be temporarily transferred to a quarantine network slice (52) by utilizing network slicing technology, thereby protecting a normal data network (61) and other user terminals (10) connected to the network.

[0085] Additionally, users can use the network slice service without interruption even if a security issue occurs.

[0086] FIG. 5 is a signal flow diagram of a network slice security management system and method according to an embodiment of the present invention in a terminal where a security issue has occurred.

[0087] As shown in Fig. 4, in step (S150), a user terminal (10) in which a security breach has occurred is connected to a quarantine network slice (52) and isolated.

[0088] In step (S160), the network slice security management system (100) resolves the security issue of the isolated user terminal using a security program provided by the quarantine data network (not shown), and the security agent (13) confirms that the security issue of the user terminal has been resolved.

[0089] In step (S170), when the security issue of the user terminal is resolved, the security agent (13) notifies the network slice agent (12) of the terminal security status.

[0090] In step (S180), the network slice agent (12) provides the notified terminal security good status to the network slice security management system (100).

[0091] In step (S190), when the network slice security management system (100) receives the terminal security good status, it requests the 5G system (50) to grant permission to access a normal network slice (51).

[0092] In step (S191), the network slice security management system (100) receives normal network slice (51) information from the 5G system (50).

[0093] In step (S192), the network slice security management system (100) provides the normal network slice information to the network slice agent (12) and requests the user terminal (10) to connect to the normal network slice (51).

[0094] In step (S200), the network slice agent (12) connects the user terminal (10) to a normal network slice (51) based on the normal network slice information, thereby normalizing the network slice service.

[0095] According to an embodiment of the present invention, not only can a terminal in which a security problem has occurred be isolated to protect a normal data network (61), but also the network slice service can be normalized without service interruption by resolving the security problem of the terminal through a security agent (13) or the like.

[0096] FIG. 6 is a signal flow diagram of a network slice security management system and method according to an embodiment of the present invention when a user terminal (10) first connects to or boots up a 5G system (50).

[0097] In step (S210), when the user terminal (10) first connects to or boots up the 5G system (50), the network slice agent (12) can basically connect the user terminal (10) to the quarantine network slice (52).

[0098] In step (S220), the network slice security management system (100) can provide installation or update of a security agent (13) to a user terminal (10) through the connected quarantine network slice.

[0099] In step (S230), the installed or updated security agent (13) checks for a security breach situation on the user terminal (10), and if there is no security problem on the user terminal (10), it notifies the network slice agent (12) of the terminal security status.

[0100] At this time, if there is a security issue in the user terminal (10), the connection to the quarantine network slice (52) can be maintained and follow-up measures of the network slice security management system (100) as described above in FIG. 5 can be performed.

[0101] In step (S240), the network slice agent (12) provides the notified terminal security status to the network slice security management system (100).

[0102] In step (S250), when the network slice security management system (100) receives the terminal security good status, it requests the 5G system (50) to grant permission to access a normal network slice (51).

[0103] In step (S251), the network slice security management system (100) receives normal network slice (51) information from the 5G system (50).

[0104] In step (S252), the network slice security management system (100) provides the normal network slice information to the network slice agent (12) and requests the user terminal (10) to connect to the normal network slice (51) through the network slice agent (12).

[0105] In step (S260), the network slice agent (12) connects the user terminal (10) to the normal network slice (51) using the provided normal network slice information, thereby providing a network slice service.

[0106] The network slice security management system according to an embodiment of the present invention requests the 5G system (50) to create and manage a network slice, manages information by setting a policy for each network slice, and provides each network slice information to the 5G system (50) and the network slice agent (12) to isolate the user terminal (10) from a normal data network (61) or to normally connect the user terminal (10) to a normal data network (61), thereby maintaining and managing the security of the user terminal (10) and the network slice service.

[0107] Meanwhile, the present invention can effectively utilize network slicing technology together with conventional network slice agents and onboarding systems to efficiently manage network resources and fulfill user requirements.

[0108] Additionally, the present invention can apply customized security policies to each network slice according to its use cases and requirements.

[0109] Furthermore, the present invention can enable monitoring and responding to security threats within a network slice by detecting antivirus and intrusions through a security agent (13).

[0110] The method according to the embodiment of the present invention described above may be implemented in the form of program commands that can be executed through various computer components and recorded on a computer-readable recording medium. The computer-readable recording medium may include program commands, data files, data structures, etc., either singly or in combination. The program commands recorded on the computer-readable recording medium may be specially designed and configured for the embodiment of the present invention, or may be known and usable by those skilled in the art of computer software. The computer-readable recording medium includes hardware configured to store and execute program commands, such as magnetic recording media such as hard disks, floppy disks, and magnetic tapes; optical recording media such as CD-ROMs and DVDs; magneto-optical media such as floptical disks; ROMs, RAMs, and flash memories. The program commands include machine language codes generated by a compiler and high-level language codes that can be executed on a computer using an interpreter. The hardware may be configured to operate as one or more software modules to process the method according to the present invention, and vice versa.

[0111] The method according to an embodiment of the present invention can be executed on an electronic device in the form of a program command. The electronic device includes a portable communication device such as a smartphone or smart pad, a computer device, a portable multimedia device, a portable medical device, a camera, a wearable device, and a home appliance.

[0112] The method according to an embodiment of the present invention may be provided as a computer program product. The computer program product may be traded as a commodity between sellers and buyers. The computer program product may be distributed in the form of a machine-readable recording medium or online through an application store. In the case of online distribution, at least a portion of the computer program product may be temporarily stored or temporarily generated on a storage medium, such as the memory of a manufacturer's server, an application store's server, or a relay server.

[0113] Each component, such as a module or program, according to an embodiment of the present invention may be composed of one or more sub-components, and some of these sub-components may be omitted, or other sub-components may be further included. Some components (modules or programs) may be integrated into a single entity and perform the same or similar functions as those performed by each respective component prior to integration. Operations performed by a module, program, or other component according to an embodiment of the present invention may be executed sequentially, in parallel, iteratively, or heuristically, or at least some operations may be executed in a different order, omitted, or other operations may be added.

[0114] The foregoing description of the present invention is for illustrative purposes only, and those skilled in the art will readily appreciate that the present invention can be readily modified into other specific forms without altering the technical spirit or essential characteristics of the present invention. Therefore, the embodiments described above should be understood as illustrative in all respects and not restrictive. For example, each component described as a single entity may be implemented in a distributed manner, and similarly, components described as distributed may be implemented in a combined manner.

[0115] The scope of the present invention is indicated by the claims set forth below, and all changes or modifications derived from the meaning and scope of the claims and their equivalent concepts should be interpreted as being included in the scope of the present invention.

[0116] The mode for carrying out the invention is described together with the best mode for carrying out the invention.

[0117] A network slice security management system and method according to an embodiment of the present invention can protect a normal network and devices connected to the network by temporarily transferring a communication network of a user terminal that has suffered a security breach, such as infection by malware, to a quarantine network slice instead of a normal network slice by utilizing network slicing technology.

Claims

1. In the network slice security management system, A security agent providing unit that installs or updates a security agent that checks for terminal security breaches on a user terminal; A security policy setting section defining the guidelines and rules required for the above security agent; and A network slice policy management unit that receives a terminal security status provided by a network slice agent installed on the user terminal based on the security breach inspection result of the security agent, and determines whether to connect the user terminal to a normal network slice or a quarantine network slice based on the terminal security status; Including, The above quarantine network slice is a network slice for connecting to a quarantine data network to isolate the user terminal in case there is a security problem with the user terminal. Network Slice Security Management System.

2. In paragraph 1, When the above network slice policy management unit receives a security breach status of the user terminal, it requests the mobile communication system to cancel the normal network slice access permission and provides the information of the quarantine network slice provided from the mobile communication system to the network slice agent. The above network slice agent connects the user terminal to the quarantine network slice based on the quarantine network slice information. Network Slice Security Management System.

3. In paragraph 2, When the above user terminal is connected to the above quarantine network slice When the above network slice policy management unit receives a terminal security good status, it requests the mobile communication system to grant permission to access the normal network slice, and provides information on the normal network slice provided from the mobile communication system to the network slice agent. The above network slice agent connects the user terminal to the normal network slice based on the normal network slice information. Network Slice Security Management System.

4. In paragraph 1, When the above user terminal is first connected to or booted up in the mobile communication system, The above network slice agent connects the user terminal to the quarantine network slice, When the above network slice policy management unit receives the good security status of the user terminal, it requests the mobile communication system to grant permission to access the normal network slice, and provides information on the normal network slice provided from the mobile communication system to the network slice agent. The above network slice agent connects the user terminal to the normal network slice based on the normal network slice information. Network Slice Security Management System.

5. In paragraph 1, The above network slice policy management unit requests the mobile communication system to create the quarantine network slice, thereby simultaneously operating a normal data network connected to the normal network slice and a quarantine data network separated end-to-end from it. Network Slice Security Management System.

6. In paragraph 5, It further includes a quarantine data network management unit that diagnoses the security breach situation of the user terminal connected to the quarantine data network and manages and resolves security issues. Network Slice Security Management System.

7. In the network slice security management method, A step in which a network slice security management system provides a security agent that checks for terminal security breaches and is installed or updated on a user terminal; The above network slice security management system sets a security policy that defines the guidelines and rules required for the security agent; and A network slice policy decision step in which the network slice security management system receives a terminal security status provided by a network slice agent installed in the user terminal based on a security breach inspection result of the security agent, and determines whether to connect the user terminal to a normal network slice or a quarantine network slice based on the terminal security status; Including, The above quarantine network slice is a network slice for connecting to a quarantine data network to isolate the user terminal in case there is a security problem with the user terminal. How to manage network slice security.

8. In paragraph 7, The above network slice policy decision step, when receiving a security breach status of the user terminal, requests the mobile communication system to cancel the normal network slice access permission, and provides information on the quarantine network slice provided from the mobile communication system to the network slice agent. The above network slice agent connects the user terminal to the quarantine network slice based on the quarantine network slice information. How to manage network slice security.

9. In paragraph 8, When the above user terminal is connected to the above quarantine network slice The above network slice policy decision step, when receiving a terminal security good status, requests the mobile communication system to grant permission to access the normal network slice, and provides information on the normal network slice provided from the mobile communication system to the network slice agent. The above network slice agent connects the user terminal to the normal network slice based on the normal network slice information. How to manage network slice security.

10. In paragraph 7, When the above user terminal is first connected to or booted up in the mobile communication system, The above network slice agent connects the user terminal to the quarantine network slice, The above network slice policy decision step, upon receiving the security good status of the user terminal, requests the mobile communication system to grant permission to access the normal network slice, and provides information on the normal network slice provided from the mobile communication system to the network slice agent. The above network slice agent connects the user terminal to the normal network slice based on the normal network slice information. How to manage network slice security.

11. In paragraph 7, The above network slice policy decision step further includes a step of requesting the mobile communication system to create the quarantine network slice, thereby simultaneously operating a normal data network connected to the normal network slice and a quarantine data network end-to-end separated therefrom. How to manage network slice security.

12. In paragraph 11, The above network slice security management system further includes a quarantine data network management step for diagnosing a security breach situation of a user terminal connected to the quarantine data network and managing and resolving security issues. How to manage network slice security.

Citation Information

Patent Citations

  • Auxiliary apparatus for welding robot

    KR1020250045722A

  • Applying subscriber-id based security, equipment-id based security, and / or network slice-id based security with user-id and syslog messages in mobile networks

    WO2024049591A1