5G Cybersecurity Protection System for Vulnerable IoT Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

5G wireless networks face increased security vulnerabilities due to the large number of connected devices, including IoT and cloud RAN devices, which are often low-cost, poorly maintained, and unsupported, making them susceptible to cyber-attacks that can compromise the entire network.

Innovation Solution

The implementation of a system that registers and monitors connected devices, creates personalized signatures, and dynamically deauthorizes at-risk devices using intelligent gNodeB nodes and core network resources to prevent cyber-attacks by identifying and isolating compromised devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional network hardening techniques are applied to secure 5G networks, then security protection is improved, but deployment cost and resource consumption increase significantly

Engineering Contradiction:
Improvenetwork securityVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables connected devices to autonomously register themselves with the 5G core network through self-service mechanisms. Devices automatically provide identification information and establish security credentials without requiring manual configuration or intervention, thereby reducing deployment complexity while maintaining security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors connected devices for security risks and dynamically adjusts authorization status based on detected threats. This feedback mechanism allows the network to respond automatically to security incidents, reducing the need for manual security management and complex deployment procedures

Inventive Principle:
Principle #23Feedback

2Reliability

If manual security configuration is applied to each connected device, then security protection is improved, but implementation time and resource consumption increase significantly

Engineering Contradiction:
Improvedevice securityVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Security credentials and authorization parameters are pre-configured in the 5G core network before devices connect. When devices register, they automatically receive appropriate security configurations based on their device type and intended use, eliminating the need for time-consuming manual security setup for each device

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements a universal security framework in the 5G core network that can serve multiple device types and scenarios through a single centralized mechanism. This multi-functional approach allows the same security infrastructure to protect diverse connected devices without requiring device-specific manual configuration

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11115824B15G cybersecurity protection system
Publication Date: 2021.09.07 T MOBILE US INC
  • US11115824B1 patent drawing
  • US11115824B1 patent drawing
  • US11115824B1 patent drawing

AI summary

The disclosed technology includes a method and system for preventing or reducing cyber-attacks in a 5G network. The system can register a connected device with the 5G network, monitor the connected device by the computing device associated with the 5G network, and detect or determine that the connected device is at risk of a cyber-attack based on one or more conditions. The conditions can include detecting that the connected device is obsolete or unmaintained, the connected device fails to respond to status checks, or a service provider associated with the connected device is not supporting the connected device or is out of business. In response to detecting or determining that the connected device is at risk of the cyber-attack, the system can deauthorize the connected device.