Communication Device Quarantine Across Network Slices for Stability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Communication networks face challenges in managing compromised communication devices, particularly IoT devices, which can cause network congestion or outage due to malicious or faulty software leading to increased transmission rates or data sizes, without effective methods to identify and isolate such devices.
Innovation Solution
A communication network employs a Network Exposure Function (NEF) to detect device anomalies or receive signaling indicating compromised devices, initiating quarantine operations by moving them to a separate network slice for management, and facilitating re-registration to a quarantine network slice.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If communication devices are allowed to operate freely in the network, then network productivity and device accessibility are improved, but network reliability deteriorates due to compromised devices causing congestion or outage
Solution Approach 1:
The network is segmented into multiple slices, with a dedicated quarantine network slice isolated from the normal network slice. Compromised devices are migrated to the quarantine slice, separating them from healthy devices. This segmentation allows the majority of the network to continue operating at full productivity while isolated compromised devices are contained and managed separately, resolving the contradiction between maintaining network throughput and ensuring network stability.
2Reliability
If compromised devices are isolated by forcing re-registration, then network reliability is improved, but device operation continuity deteriorates due to service interruption during re-registration
Solution Approach 1:
The network performs preliminary actions by proactively detecting compromised devices through anomaly detection mechanisms before they can cause significant harm. Once detected, the network initiates forced re-registration to migrate devices to the quarantine slice. This preliminary action approach improves network security by early containment, while the service interruption is minimized because the detection and migration process is automated and rapid, preventing prolonged service disruption.
3Difficulty of detecting and measuring
If network monitoring and detection capabilities are enhanced, then ability to detect compromised devices is improved, but network complexity increases due to additional monitoring functions
Solution Approach 1:
The Network Exposure Function (NEF) serves as an intermediary component that provides standardized interfaces and mechanisms for detecting compromised devices. Rather than distributing complex detection logic across multiple network elements, the NEF centralizes the anomaly detection functionality, offering a unified approach to identify compromised devices. This intermediary role improves detection capability while managing network complexity by consolidating monitoring functions in a dedicated network element.
Data Source
Figure 1
Figure 2A~2B
Figure 3
AI summary
A communication network (10) provides communicative coupling between potentially large populations of Internet-of-Things (IoT) devices (12) and/or other types of communication devices (12) and one or more Application Servers (ASs) (14) that are affiliated with respective ones of the communication devices (12). One or more network functions (30, 58) in the communication network (10) are operative to determine that any given one of the communication devices (12) is compromised, or that multiple such devices (12) are compromised, and provide for management of such devices (12) within the network (10) as "compromised" devices (12). Aspects of compromised-device management include forcing re-registration of such devices (12), for quarantining them in one or more quarantine network slices(54), and recovering quarantined devices (12) after remediation of the compromise. Recovery operations include forcing re-registration of devices (12) being recovered, for migration back to their normal or regular network slice(s) (50).