5G Network Security System with Distributed Traffic Segregation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

5G networks face increased security vulnerabilities due to diverse communication types and devices, with conventional network hardening techniques being impractical for deployment across a vast and diverse network.

Innovation Solution

A 5G network security system that uses a vulnerability-risk-threat (VRT) framework to monitor and control network traffic, dynamically instantiating security measures to segregate trusted network devices from untrusted external networks, and employing tools to manage diverse data forms and thwart cyberattacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional network hardening techniques are applied to secure 5G networks, then security vulnerability mitigation is improved, but deployment cost and resource consumption become prohibitive

Engineering Contradiction:
Improvenetwork securityVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network security function into a distributed architecture where security agents are deployed at individual network access nodes (base stations, core network functions) rather than requiring centralized hardening of the entire network. This allows security to be implemented locally at each node, reducing overall deployment complexity while maintaining network-wide security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a security agent as an intermediary component that runs at each network access node. This agent acts as a mediator between the network traffic and the security policies, implementing security functions locally without requiring direct modification or hardening of the core network infrastructure, thereby reducing deployment complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive security measures are deployed across all 5G network devices, then network security is improved, but resource consumption and cost increase significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements local quality by deploying security agents only at specific network access nodes where they are needed, rather than uniformly across all network devices. Each agent operates independently at its local location, providing security where required while minimizing overall resource consumption across the network.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The security agent is designed to be self-contained and self-managing at each network access node. It autonomously monitors local traffic, enforces security policies, and manages its own operation without requiring continuous centralized resource allocation, thereby reducing overall network resource consumption while maintaining security.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If security systems process and sort all network traffic, then cyberattack mitigation is improved, but processing time and system complexity increase

Engineering Contradiction:
Improvecyberattack mitigationVSAvoidtraffic processing time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The security agent performs preliminary actions by pre-classifying and pre-processing network traffic at the network access node before traffic enters the core network. Suspicious traffic is identified and segregated early in the traffic flow, allowing subsequent security processing to focus only on potentially malicious traffic rather than all traffic, thereby reducing processing time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments traffic processing into multiple stages: initial filtering and classification by the security agent, followed by detailed analysis only of suspicious traffic. This segmentation allows the majority of benign traffic to pass through quickly while applying comprehensive security analysis only where needed, reducing overall processing time while maintaining effective cyberattack mitigation.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12245039B2Security system for managing 5G network traffic background
Publication Date: 2025.03.04 T MOBILE US INC
  • US12245039B2 patent drawing
  • US12245039B2 patent drawing
  • US12245039B2 patent drawing

AI summary

The technology includes a method performed by a system of a telecommunications network to manage network traffic of a 5G network. The system can instantiate a security system to sort incoming or outgoing network traffic at a perimeter of the 5G network into multiple groups that are each uniquely associated with multiple traffic types and multiple security levels. The system can inspect segments of data included in the incoming network traffic and sort multiple portions of the network traffic into the groups based in part on the inspection of the segments of the data. The system can dynamically adjust an available bandwidth of the 5G network based on each load of each of the groups and dispatch the portions of the network traffic in accordance with a traffic type and a security level of each of the groups.