5G Private Network Slice for Secure Remote Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for secure remote access mechanisms in enterprise private 5G networks to enable safe and secure management and monitoring of systems, as existing solutions lack robust security measures for sensitive data and operations.

Innovation Solution

The implementation of a custom enterprise private network slice within a 5G network, facilitated by Multi-access Edge Computing (MEC) or other suitable services, which uses traffic splitting functionality to route enterprise user plane traffic through a secure tunnel while routing subscriber traffic to the public network, employing OAuth 2.0 for authorization and utilizing network functions like UPF and SMF for secure access and forwarding rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If enterprise user plane traffic is routed through the public network for remote access, then ease of operation is improved, but security is worsened due to exposure of sensitive data

Engineering Contradiction:
Improveremote access capabilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The network traffic is segmented into enterprise user plane traffic and subscriber traffic, with enterprise traffic routed through a private network slice while subscriber traffic uses the public network. This segmentation allows remote access functionality to be maintained while isolating sensitive enterprise data from public network exposure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A private network slice acts as an intermediary between enterprise user plane traffic and the core network functions. This intermediary provides a secure tunnel that enables remote access to monitor and control enterprise systems without directly exposing sensitive data to the public network.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If a private network slice is implemented to secure enterprise traffic, then security is improved, but device complexity is worsened due to additional network functions

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork architecture complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The private network slice utilizes existing 5G core network functions (SMF, UPF, AMF) that already serve multiple purposes. The SMF manages both slice-specific and general subscriber sessions, while the UPF handles both enterprise and public traffic, reducing the need for entirely new specialized components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The enterprise private network slice is nested within the broader 5G network infrastructure. The slice-specific network functions are embedded within and leverage the existing core network functions, creating a hierarchical structure where the private slice operates as a virtualized layer atop the shared physical infrastructure.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Object-affected harmful factors

If token validation and authorization procedures are implemented, then security is improved, but loss of time is worsened due to additional authentication steps

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

OAuth 2.0 tokens are obtained and validated in advance before enterprise user plane traffic is routed through the private network slice. The authorization server pre-issues tokens that encode user permissions and identity information, allowing subsequent traffic to be authenticated quickly without repeated full authentication cycles.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10785652B1Secure remote access to a 5G private network through a private network slice
Publication Date: 2020.09.22 CISCO TECHNOLOGY INC
  • US10785652B1 patent drawing
  • US10785652B1 patent drawing
  • US10785652B1 patent drawing

AI summary

In one illustrative example, a network node may receive, from a user equipment (UE), a message indicating a token authorization request for access to a custom, enterprise private network slice of a 5G network. The message may include a token provided to the UE by an enterprise server of an enterprise private network of the enterprise. The network node may perform a token validation procedure and, based on a successful token validation, send a message for causing a provisioning of one or more rules in a forwarding entity of the 5G network, for causing enterprise user plane (UP) traffic of the UE to be forwarded to an anchor UPF of the private network slice. The enterprise UP traffic communication may be used for the remote control and/or monitoring of elements in a private 5G network of the enterprise.