5G Network Security Monitoring With Encrypted Packet Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network systems, particularly in 5G communication networks, lack effective methods to quickly identify and address performance degradation and security threats, leading to inefficiencies in system operation and increased costs due to undetected bottlenecks and vulnerabilities.

Innovation Solution

A network security monitoring server apparatus that mirrors and decrypts packets within a 5G non-public network, calculates performance indicators, and alerts on abnormalities, integrating with a security controller to manage and respond to network issues.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional network monitoring methods are used where each department individually assesses problems, then device complexity is reduced, but measurement precision and response time deteriorate

Engineering Contradiction:
Improveproblem identification accuracyVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent combines network monitoring, security monitoring, and performance monitoring functions into a single integrated monitoring server. This unified system receives packets from multiple sources (network devices, security terminals, performance terminals) and processes them centrally, thereby improving measurement precision while managing complexity through consolidation rather than proliferation of separate systems

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The monitoring server is designed with multi-functional capabilities to handle diverse monitoring tasks including network security analysis, performance metric calculation, and anomaly detection. By making the system universal and capable of performing multiple functions, the patent achieves high measurement precision across different monitoring dimensions without requiring separate specialized systems for each function

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If IP encryption is used for security, then security improves, but measurement precision and monitoring capability deteriorate

Engineering Contradiction:
Improvenetwork securityVSAvoidpacket analysis accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent introduces a packet decryption module as an intermediary between the encrypted packet source and the analysis functions. This mediator decrypts packets using stored IP encryption keys, allowing the monitoring system to maintain security (packets remain encrypted during transmission) while enabling precise analysis (packets are decrypted for inspection). The intermediary resolves the contradiction by providing both security preservation and analysis capability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary decryption of packets before they reach the analysis stage. By decrypting packets in advance using pre-stored encryption keys, the system ensures that security is maintained during transmission while analysis accuracy is preserved during inspection. This preliminary action allows the system to handle encrypted traffic without sacrificing monitoring precision

Inventive Principle:
Principle #10Preliminary action

3Productivity

If real-time packet mirroring and analysis is implemented, then productivity and response time improve, but use of energy and device complexity increase

Engineering Contradiction:
Improveperformance degradation detection speedVSAvoidmonitoring server energy consumption
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The patent extracts only the essential and necessary packet information for performance and security analysis, rather than processing complete packet contents. By taking out only the critical data elements needed for detection, the system achieves high productivity in identifying performance degradation while reducing the computational energy required compared to full packet analysis

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs partial analysis on mirrored packets, focusing only on specific parameters and metrics relevant to performance degradation and security threats. This partial action approach enables rapid detection (high productivity) without the energy cost of comprehensive full-packet inspection, resolving the contradiction between speed and energy consumption

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12445849B2Apparatus, system, and method for monitoring network security and performance
Publication Date: 2025.10.14 MAGDATA INC
  • US12445849B2 patent drawing
  • US12445849B2 patent drawing
  • US12445849B2 patent drawing

AI summary

One aspect of the present invention discloses a method by which a network security monitoring apparatus monitors a 5G network. The method by which a network monitoring apparatus monitors a 5G network, according to one aspect of the present invention, comprises the steps of: mirroring and receiving a packet transmitted from a user terminal to a 5G core network and transmitted to a common network through at least one security module; and calculating an index related to network performance by monitoring the mirrored packet, wherein the at least one security module is located between a user plane function (UPF)-related module of the 5G core network and the common network and performs a security-related operation on data from the user terminal, and the network monitoring apparatus is located between the UPF-related module of the 5G core network and the common network and calculates the index related to the network performance according to mirroring of the packet transmitted through the at least one security module.