5G Network Slice Security Assurance Orchestration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G network slicing lacks comprehensive mechanisms for continuous security assurance and dynamic adaptation to cyber-attacks, leading to difficulties in maintaining security levels and potential service disruptions.

Innovation Solution

The implementation of Security Assurance Levels (SALs) for network slices, using a unique scoring system to evaluate assets and enable dynamic transitions to higher SALs, combined with true end-to-end monitoring and orchestration, allows for tailored security solutions based on customer risk appetite and budget, ensuring minimal service disruption during attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If network slicing is implemented to increase network efficiency and performance, then network productivity is improved, but security assurance becomes more difficult to maintain

Engineering Contradiction:
Improvenetwork efficiencyVSAvoidsecurity assurance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent divides the network into multiple isolated network slices, each with dedicated security policies and security assurance levels. This segmentation allows different security requirements to be applied to different slices while maintaining overall network efficiency through virtualization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements differentiated security assurance levels (SALs) for different network slices based on their specific requirements. Each slice can have customized security policies, isolation levels, and protection mechanisms tailored to its particular needs rather than applying uniform security across the entire network.

Inventive Principle:
Principle #3Local quality

2Reliability

If dynamic security monitoring and adaptation mechanisms are implemented, then security assurance is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity assuranceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements continuous security monitoring that provides feedback to the orchestration system. This feedback loop enables dynamic detection of security threats and automatic adaptation of security policies in real-time, improving security assurance through ongoing observation and response.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent enables the network orchestration system to automatically detect security threats, evaluate their impact, and implement mitigation measures without human intervention. The system self-adjusts security policies and isolates affected network slices, reducing the need for complex manual security management.

Inventive Principle:
Principle #25Self-service

3Reliability

If continuous security monitoring is implemented, then security assurance is improved, but loss of time for service disruption increases

Engineering Contradiction:
Improvesecurity assuranceVSAvoidservice disruption time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent pre-configures security policies, isolation mechanisms, and mitigation strategies for different network slices before threats occur. When security incidents are detected, the system can immediately activate pre-prepared responses, minimizing service disruption time while maintaining continuous security monitoring.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12262206B2Methods and systems for 5G slicing based on dynamic security properties
Publication Date: 2025.03.25 VERIZON PATENT & LICENSING INC
  • US12262206B2 patent drawing
  • US12262206B2 patent drawing
  • US12262206B2 patent drawing

AI summary

Systems and methods enable the provisioning of security as a service for network slices. A network device stores definitions of multiple security assurance levels for network slices based on security parameters of assets used in the network slices. The network device stores multiple network slice templates, wherein the multiple network slice templates have different security assurance levels, of the multiple security assurance levels, for a Network Service Descriptor (NSD). The network device receives a request for a network slice with a requested security assurance level, of the multiple security assurance levels, for the NSD, and deploys the network slice using one of the network slice templates that has a security assurance level that corresponds to the requested security assurance level. The network device monitors the security parameters of the assets of the network slice for changes to the security assurance level of the deployed network slice.