AMF Relocation via Security Gateway Failover

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current NFV architectures in mobile networks, particularly in 5G, face challenges in ensuring the security of the N2 interface due to lack of encryption functionality, and existing redundancy mechanisms struggle with failover processes during security gateway overload or failure, which can compromise the security of data traffic.

Innovation Solution

Implementing a distributed architecture that relocates Access and Mobility Management Functions (AMFs) and security gateways across multiple geo-redundant data centers, enabling the reestablishment of secure connections by switching traffic through encrypted tunnels between radio interfaces and AMFs during security gateway failure or overload conditions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If security gateways are deployed in centralized data centers, then security management is simplified, but the system becomes vulnerable to single points of failure and overload

Engineering Contradiction:
Improvesecurity management simplicityVSAvoidsystem availability during failure
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the centralized security gateway function into distributed security gateway instances deployed across multiple data centers. Each data center hosts its own security gateway instance, eliminating the single point of failure. This segmentation maintains security management simplicity while improving reliability through geographic distribution.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a geographic dimension to security gateway deployment by distributing instances across multiple data centers located in different geographic regions. This dimensional change transforms the architecture from centralized to distributed, enabling failover capabilities while maintaining operational simplicity through standardized deployment patterns.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Device complexity

If Access and Mobility Management Functions are co-located with security gateways in single data centers, then connection establishment is simplified, but the network loses resilience during data center failure

Engineering Contradiction:
Improveconnection establishment complexityVSAvoidnetwork resilience during failure
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the AMF and security gateway functions into separate but coordinated instances across multiple data centers. Each data center hosts an AMF instance and corresponding security gateway instance, creating independent functional units that can failover independently, maintaining connection simplicity while improving resilience.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates copied instances of both AMF and security gateway functions in multiple data centers. These copies maintain identical functionality and can take over seamlessly when the primary instance fails, preserving connection establishment simplicity while providing network resilience through redundant copies.

Inventive Principle:
Principle #26Copying

3Stability of the object's composition

If manual installation and configuration of network functions is used, then hardware compatibility is ensured, but deployment time and operational costs increase

Engineering Contradiction:
Improvehardware compatibilityVSAvoiddeployment speed
Core Design Contradiction:
Stability of the object's compositionVSProductivity

Solution Approach 1:

The patent replaces manual mechanical installation and configuration processes with automated virtualization technologies. Network functions are deployed as virtual machine images that can be automatically instantiated and configured across hardware platforms, ensuring hardware compatibility through standardized virtualization interfaces while dramatically increasing deployment productivity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the deployment parameters from manual physical installation to automated virtual machine provisioning. By parameterizing the deployment process through virtualization management systems, the patent maintains hardware compatibility through standardized interfaces while improving deployment speed and reducing operational costs through automation.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240056803A1Access and mobility management function relocation due to security gateway overload/failure
Publication Date: 2024.02.15 VERIZON PATENT & LICENSING INC
  • US20240056803A1 patent drawing
  • US20240056803A1 patent drawing
  • US20240056803A1 patent drawing

AI summary

A device establishes a first encrypted tunnel with a first active security gateway at a first data center to enable the device to communicate, via the first encrypted tunnel, with a first access and mobility management function (AMF) at the first data center. The device forwards, via the first encrypted tunnel and the first active security gateway, a first User Equipment device (UE) message to the first AMF. The device determines an occurrence of a failure or overload condition at the first active security gateway, and establishes, based on the determined occurrence of the failure or overload condition, a second encrypted tunnel with a standby security gateway at a second data center to enable the device to communicate, via the second encrypted tunnel, with the first AMF. The device forwards, via the second encrypted tunnel and the standby security gateway, at least one second UE message to the first AMF.