Cloud-Native Wireless Security Slicing for Malicious Traffic Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cellular networks lack effective screening and monitoring of user equipment devices (UE devices) to identify and isolate suspicious or malicious activities, leading to potential propagation of harmful network traffic and reputational harm for both users and providers.

Innovation Solution

Implementing a cloud-native wireless network with network slicing and a scrubbing center to isolate UE devices deemed as bad actors into a separate security network slice, routing their traffic through a monitoring module that scrubs and manages bandwidth to prevent undesirable actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If UE devices are allowed to access the network without screening, then network access speed and ease of operation are improved, but harmful factors and reliability deteriorate due to malicious activities

Engineering Contradiction:
Improvenetwork accessVSAvoidmalicious network traffic
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary screening and monitoring of UE devices before allowing full network access. The cloud-native core network monitors network traffic and identifies suspicious devices in advance, assigning them to a security network slice before they can propagate harmful traffic across the entire network.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A security network slice acts as an intermediary between malicious UE devices and the main network. Suspicious devices are routed through this isolated slice with monitoring capabilities, preventing direct interaction with trusted devices while still allowing controlled access to internet services.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If all network traffic is routed through a monitoring module, then reliability and security are improved, but device complexity and processing time increase

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network is segmented into multiple slices: a security network slice for monitored suspicious devices and regular network slices for trusted devices. This segmentation allows monitoring resources to be focused only on devices that need it, reducing overall network complexity while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different quality levels of monitoring are applied to different network segments. Trusted devices experience standard network performance with minimal monitoring, while devices in the security slice receive enhanced monitoring and traffic scrubbing, optimizing the balance between security and performance.

Inventive Principle:
Principle #3Local quality

3Object-affected harmful factors

If suspicious devices are isolated to a separate network slice, then harmful factors are reduced, but loss of information and communication efficiency worsen

Engineering Contradiction:
Improvemalicious traffic propagationVSAvoidnetwork communication
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The harmful element (suspicious UE devices) is extracted from the main network and placed in a separate security network slice. This extraction prevents malicious traffic from propagating to the internet and affecting other devices, while the extracted devices retain limited communication capabilities for legitimate needs.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The isolation of suspicious devices to a security slice converts a harmful situation into a beneficial one. The monitoring and scrubbing center can analyze traffic patterns, identify threats, and protect the broader network, turning potentially harmful traffic into valuable security intelligence.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

4Object-affected harmful factors

If bandwidth is limited for devices in the security network slice, then harmful factors are controlled, but productivity and user experience deteriorate

Engineering Contradiction:
Improveundesirable network trafficVSAvoidnetwork throughput
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

Instead of completely blocking all traffic from suspicious devices, the system applies partial monitoring and scrubbing to their traffic. The security slice allows limited bandwidth and controlled communication, providing enough throughput for legitimate needs while preventing harmful traffic propagation.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250220435A1Security network slice for cloud-based wireless networks
Publication Date: 2025.07.03 BOOST SUBSCRIBERCO LLC
  • US20250220435A1 patent drawing
  • US20250220435A1 patent drawing
  • US20250220435A1 patent drawing

AI summary

A method includes receiving information representative of one or more actions taken by a user equipment device connected to a cloud-native wireless network. The method also includes selecting, based on the information, the user equipment device for monitoring network traffic originating from the user equipment device. The method also includes, in response to selecting the user equipment device, assigning the user equipment device to a network slice of the cloud-native wireless network, wherein the user equipment device is assigned to the network slice upon connecting to a radio tower of the cloud-native wireless network. The method also includes routing network traffic associated with the network slice through a module of the cloud-native wireless network that monitors the network traffic.