5G Network Security System with Distributed Traffic Segregation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
5G networks face increased security vulnerabilities due to diverse communication types and devices, with conventional network hardening techniques being impractical for deployment across a vast and diverse network.
Innovation Solution
A 5G network security system that uses a vulnerability-risk-threat (VRT) framework to monitor and control network traffic, dynamically instantiating security measures to segregate trusted network devices from untrusted external networks, and employing tools to manage diverse data forms and thwart cyberattacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional network hardening techniques are applied to secure 5G networks, then security vulnerability mitigation is improved, but deployment cost and resource consumption become prohibitive
Solution Approach 1:
The patent segments the network security function into a distributed architecture where security agents are deployed at individual network access nodes (base stations, core network functions) rather than requiring centralized hardening of the entire network. This allows security to be implemented locally at each node, reducing overall deployment complexity while maintaining network-wide security.
Solution Approach 2:
The patent introduces a security agent as an intermediary component that runs at each network access node. This agent acts as a mediator between the network traffic and the security policies, implementing security functions locally without requiring direct modification or hardening of the core network infrastructure, thereby reducing deployment complexity.
2Reliability
If comprehensive security measures are deployed across all 5G network devices, then network security is improved, but resource consumption and cost increase significantly
Solution Approach 1:
The patent implements local quality by deploying security agents only at specific network access nodes where they are needed, rather than uniformly across all network devices. Each agent operates independently at its local location, providing security where required while minimizing overall resource consumption across the network.
Solution Approach 2:
The security agent is designed to be self-contained and self-managing at each network access node. It autonomously monitors local traffic, enforces security policies, and manages its own operation without requiring continuous centralized resource allocation, thereby reducing overall network resource consumption while maintaining security.
3Object-affected harmful factors
If security systems process and sort all network traffic, then cyberattack mitigation is improved, but processing time and system complexity increase
Solution Approach 1:
The security agent performs preliminary actions by pre-classifying and pre-processing network traffic at the network access node before traffic enters the core network. Suspicious traffic is identified and segregated early in the traffic flow, allowing subsequent security processing to focus only on potentially malicious traffic rather than all traffic, thereby reducing processing time.
Solution Approach 2:
The patent segments traffic processing into multiple stages: initial filtering and classification by the security agent, followed by detailed analysis only of suspicious traffic. This segmentation allows the majority of benign traffic to pass through quickly while applying comprehensive security analysis only where needed, reducing overall processing time while maintaining effective cyberattack mitigation.
Data Source
AI summary
The technology includes a method performed by a system of a telecommunications network to manage network traffic of a 5G network. The system can instantiate a security system to sort incoming or outgoing network traffic at a perimeter of the 5G network into multiple groups that are each uniquely associated with multiple traffic types and multiple security levels. The system can inspect segments of data included in the incoming network traffic and sort multiple portions of the network traffic into the groups based in part on the inspection of the segments of the data. The system can dynamically adjust an available bandwidth of the 5G network based on each load of each of the groups and dispatch the portions of the network traffic in accordance with a traffic type and a security level of each of the groups.


