5G SBA Cybersecurity System with Dynamic Resource Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

5G wireless networks introduce new cybersecurity threats due to increased data volumes and vulnerabilities, making conventional security techniques cost-prohibitive and resource-intensive to deploy effectively across diverse networks.

Innovation Solution

A cybersecurity system for Service-Based Architecture (SBA) that monitors and protects network traffic through a common interface, prioritizes security resources for frequently and recently used network functions, and employs vulnerability-risk threat services to mitigate cyberattacks by intercepting and redirecting high-risk data for external collection and sanitization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security techniques are deployed across diverse 5G networks, then security coverage is improved, but cost and resource consumption become prohibitive

Engineering Contradiction:
Improvesecurity coverageVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent implements a universal security service that can be deployed across diverse 5G network elements (base stations, core network elements, access points) providing multi-functional security protection. This service offers authentication, authorization, accounting, and threat detection capabilities that work across different network types and vendors, eliminating the need for separate security solutions for each network element and reducing overall resource consumption.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The security system is segmented into distributed security services deployed at network edges and a centralized security management platform. This segmentation allows local security functions to operate independently with minimal resource consumption while the centralized platform provides coordination and policy management, reducing the burden on individual network elements.

Inventive Principle:
Principle #1Segmentation

2Reliability

If security resources are allocated to protect all network elements, then security comprehensiveness is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity comprehensivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges security functions into a unified security service that handles authentication, authorization, accounting, and threat detection in a single integrated framework. This consolidation reduces system complexity by eliminating redundant security mechanisms across different network elements while maintaining comprehensive security coverage through the unified service.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security service acts as an intermediary between network elements and external threats, providing a standardized interface for security operations. This intermediary role simplifies the system architecture by centralizing security logic and providing consistent security policies across diverse network elements without requiring each element to implement complex security mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If monitoring is performed on all network traffic, then threat detection accuracy is improved, but processing overhead increases

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidprocessing overhead
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The security service implements local quality monitoring by analyzing traffic characteristics specific to different network contexts and threat types. Instead of applying uniform deep packet inspection to all traffic, the system adapts monitoring intensity and methods based on local conditions, traffic patterns, and threat likelihood, reducing processing overhead while maintaining detection accuracy for relevant threats.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system applies partial monitoring actions by focusing security analysis on suspicious or anomalous traffic patterns rather than examining every packet in detail. The security service uses lightweight inspection for normal traffic and intensifies monitoring only when threats are detected or suspected, reducing overall processing overhead while maintaining high detection accuracy for actual threats.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11799897B2Cybersecurity system for common interface of service-based architecture of a wireless telecommunications network
Publication Date: 2023.10.24 T MOBILE US INC
  • US11799897B2 patent drawing
  • US11799897B2 patent drawing
  • US11799897B2 patent drawing

AI summary

A method performed by a cybersecurity system includes monitoring multiple network functions (NFs) of a service-based architecture (SBA) of a 5G network. The NFs are communicatively interconnected over an HTTP/2 interface. The cybersecurity system detects potentially malicious network traffic communicated over the HTTP/2 interface, identifies a NFs or associated services that are susceptible to a cyberattack based on the potentially malicious network traffic and deploys resources to secure the NFs or associated services. In one example, the resources are prioritized for a most frequently used (MFU) or most recently used (MRU) NF or associated service.