Cybersecurity System for 5G Edge Protection via SEPP

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

5G wireless networks introduce new cybersecurity threats due to increased data volumes and vulnerabilities, making conventional security techniques cost-prohibitive and resource-intensive to deploy effectively across diverse network elements and services.

Innovation Solution

A cybersecurity system that monitors and protects Network Functions (NFs) and services in a Service-Based Architecture (SBA) by intercepting network traffic, prioritizing security resources for frequently and recently used NFs, and utilizing a vulnerability-risk threat service to dynamically redirect high-risk data for collection and sanitization, while also standardizing signaling traffic at Security Edge Protection Proxies (SEPPs) to mitigate cyberattacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security techniques are deployed across diverse network elements and services in 5G networks, then security coverage is improved, but deployment cost and resource consumption become prohibitive

Engineering Contradiction:
Improvesecurity coverageVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a Security Edge Protection Proxy (SEPP) as an intermediary component that sits between network functions and external networks. The SEPP centralizes security operations including traffic interception, inspection, and threat mitigation, eliminating the need to deploy security resources across every network element. This mediator approach resolves the contradiction by providing comprehensive security coverage through a single centralized point rather than distributed deployment across all network elements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The SEPP is designed as a universal security component that handles multiple security functions including traffic inspection, threat detection, malware filtering, and secure communication protocols. By consolidating these diverse security operations into a single multi-functional entity, the system achieves broad security coverage without the complexity of deploying specialized security solutions for each network element or service type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If security resources are distributed across all network functions, then security monitoring is improved, but resource efficiency deteriorates

Engineering Contradiction:
Improvesecurity monitoringVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The SEPP acts as a centralized intermediary that intercepts and inspects all network traffic passing through it, providing comprehensive security monitoring without requiring security resources to be distributed across all network functions. This centralized monitoring approach maintains thorough surveillance capabilities while significantly reducing overall resource consumption by eliminating redundant security operations at multiple distributed points.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent merges multiple security monitoring functions into a single SEPP entity that consolidates traffic inspection, threat detection, and security policy enforcement. By combining these functions that would otherwise be distributed across numerous network elements, the system achieves equivalent or superior monitoring coverage while reducing total resource consumption through shared infrastructure and eliminated redundancy.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If comprehensive security inspection is performed on all network traffic, then threat detection is improved, but processing time increases

Engineering Contradiction:
Improvethreat detectionVSAvoidprocessing delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The SEPP performs preliminary security inspections and filtering on network traffic before it reaches internal network functions. By conducting initial threat detection and blocking obviously malicious traffic at the edge, the system reduces the volume of traffic requiring deeper inspection later, thereby maintaining high threat detection capabilities while minimizing processing delays for legitimate traffic.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security inspection process is optimized by applying different levels of scrutiny to different types of traffic. The SEPP performs rapid filtering on common traffic patterns and reserves more intensive inspection resources for suspicious or high-risk traffic. This localized quality approach ensures thorough threat detection for problematic traffic while maintaining fast processing for normal traffic, resolving the contradiction between detection completeness and processing speed.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11863990B2Cybersecurity system for edge protection of a wireless telecommunications network
Publication Date: 2024.01.02 T MOBILE US INC
  • US11863990B2 patent drawing
  • US11863990B2 patent drawing
  • US11863990B2 patent drawing

AI summary

A method performed by a system includes instantiating a vulnerability-risk-threat (VRT) service for a security edge protection proxy (SEPP) element of a 5G telecommunications network. The system intercepts and parameterizes network traffic of the SEPP element to identify network functions (NFs) or associated services that requires cybersecurity protection and selects security resources for protecting the identified NFs or associated services. The system prioritizes an NF or associated service that is most frequently used (MFU) or most recently used (MRU) and then allocates the security resources in accordance with the prioritization.