Cybersecurity System for 5G Edge Protection via SEPP
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
5G wireless networks introduce new cybersecurity threats due to increased data volumes and vulnerabilities, making conventional security techniques cost-prohibitive and resource-intensive to deploy effectively across diverse network elements and services.
Innovation Solution
A cybersecurity system that monitors and protects Network Functions (NFs) and services in a Service-Based Architecture (SBA) by intercepting network traffic, prioritizing security resources for frequently and recently used NFs, and utilizing a vulnerability-risk threat service to dynamically redirect high-risk data for collection and sanitization, while also standardizing signaling traffic at Security Edge Protection Proxies (SEPPs) to mitigate cyberattacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional security techniques are deployed across diverse network elements and services in 5G networks, then security coverage is improved, but deployment cost and resource consumption become prohibitive
Solution Approach 1:
The patent introduces a Security Edge Protection Proxy (SEPP) as an intermediary component that sits between network functions and external networks. The SEPP centralizes security operations including traffic interception, inspection, and threat mitigation, eliminating the need to deploy security resources across every network element. This mediator approach resolves the contradiction by providing comprehensive security coverage through a single centralized point rather than distributed deployment across all network elements.
Solution Approach 2:
The SEPP is designed as a universal security component that handles multiple security functions including traffic inspection, threat detection, malware filtering, and secure communication protocols. By consolidating these diverse security operations into a single multi-functional entity, the system achieves broad security coverage without the complexity of deploying specialized security solutions for each network element or service type.
2Reliability
If security resources are distributed across all network functions, then security monitoring is improved, but resource efficiency deteriorates
Solution Approach 1:
The SEPP acts as a centralized intermediary that intercepts and inspects all network traffic passing through it, providing comprehensive security monitoring without requiring security resources to be distributed across all network functions. This centralized monitoring approach maintains thorough surveillance capabilities while significantly reducing overall resource consumption by eliminating redundant security operations at multiple distributed points.
Solution Approach 2:
The patent merges multiple security monitoring functions into a single SEPP entity that consolidates traffic inspection, threat detection, and security policy enforcement. By combining these functions that would otherwise be distributed across numerous network elements, the system achieves equivalent or superior monitoring coverage while reducing total resource consumption through shared infrastructure and eliminated redundancy.
3Reliability
If comprehensive security inspection is performed on all network traffic, then threat detection is improved, but processing time increases
Solution Approach 1:
The SEPP performs preliminary security inspections and filtering on network traffic before it reaches internal network functions. By conducting initial threat detection and blocking obviously malicious traffic at the edge, the system reduces the volume of traffic requiring deeper inspection later, thereby maintaining high threat detection capabilities while minimizing processing delays for legitimate traffic.
Solution Approach 2:
The security inspection process is optimized by applying different levels of scrutiny to different types of traffic. The SEPP performs rapid filtering on common traffic patterns and reserves more intensive inspection resources for suspicious or high-risk traffic. This localized quality approach ensures thorough threat detection for problematic traffic while maintaining fast processing for normal traffic, resolving the contradiction between detection completeness and processing speed.
Data Source
AI summary
A method performed by a system includes instantiating a vulnerability-risk-threat (VRT) service for a security edge protection proxy (SEPP) element of a 5G telecommunications network. The system intercepts and parameterizes network traffic of the SEPP element to identify network functions (NFs) or associated services that requires cybersecurity protection and selects security resources for protecting the identified NFs or associated services. The system prioritizes an NF or associated service that is most frequently used (MFU) or most recently used (MRU) and then allocates the security resources in accordance with the prioritization.


