Cloud Account Security Group Segmentation for 5G Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-based 5G networks face challenges in detecting and remediating irregularities in user account permissions and network structures, leading to potential security vulnerabilities due to dynamic user roles and access changes, as well as virtualized resource management.

Innovation Solution

The system retrieves native and non-native data for cloud accounts, compares it to a security policy, and modifies accounts by adjusting security groups and access permissions to enforce least privilege access, thereby detecting and remedying deviations from the policy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If user accounts are granted broad access permissions to support dynamic user roles and services, then service versatility and adaptability improve, but security vulnerabilities and unauthorized access risks increase

Engineering Contradiction:
Improveservice versatilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments user accounts into multiple security groups with differentiated permission levels. Each security group represents a distinct access tier, allowing the system to grant broad access to specific groups while maintaining overall security through granular control. This segmentation enables service versatility for authorized users while preventing unauthorized access by isolating permissions across different security groups.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by assigning different permission characteristics to different security groups. Rather than applying uniform access controls, the system tailors permission levels to specific user roles and service requirements. Each security group receives precisely the access rights needed for its function, enabling adaptability for legitimate operations while minimizing security vulnerabilities through role-based access differentiation.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If access permissions are frequently adjusted to accommodate changing user roles, then operational flexibility improves, but permission drift and security policy violations increase

Engineering Contradiction:
Improveoperational flexibilityVSAvoidpermission accuracy
Core Design Contradiction:
Adaptability or versatilityVSManufacturing precision

Solution Approach 1:

The patent applies preliminary action by pre-defining multiple security groups with predetermined permission sets before users are assigned to roles. When user roles change, the system moves users between pre-configured security groups rather than creating ad-hoc permission changes. This approach maintains operational flexibility for role changes while preventing permission drift, as all access permissions are established in advance through standardized security group definitions that enforce security policies.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms to monitor and detect permission drift across security groups. The system continuously compares actual access permissions against defined security policies and generates alerts when deviations are detected. This feedback loop enables the system to maintain high permission accuracy even as user roles change frequently, as administrators can quickly identify and correct any drift from authorized access patterns.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If comprehensive security monitoring is implemented across all cloud accounts, then security detection capability improves, but system complexity and computational overhead increase

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments security monitoring by security group, rather than implementing monolithic monitoring across all cloud accounts. Each security group can be monitored independently with appropriate detection rules tailored to its specific permissions and risks. This segmentation improves security detection capability for each group while reducing overall system complexity by breaking down the monitoring task into manageable, modular components that can be configured and maintained separately.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20240372872A1Multi-account security in cloud-based 5g network
Publication Date: 2024.11.07 BOOST SUBSCRIBERCO LLC
  • US20240372872A1 patent drawing
  • US20240372872A1 patent drawing
  • US20240372872A1 patent drawing

AI summary

Systems, methods, and devices manage security controls associated with cloud accounts in a virtual private cloud. An example process includes retrieving native data and nonnative data for the cloud accounts. The cloud accounts comprise cloud roles that have access to cloud resources. Data for identities mapped to the cloud roles is retrieved. The identities are mapped in an identity management system. The retrieved native data for the cloud accounts, the retrieved nonnative data for the cloud accounts, and the retrieved data for the identities mapped to the cloud roles are compared to a security policy to identify a deviation in a cloud account from the cloud accounts. The cloud account is modified to remediate the deviation from the security policy.