Disjoint Network Path Security for 5G Core

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cellular communication systems, especially 5G core networks, trusted Network Functions (NFs) can be compromised, leading to security threats, and existing methods lack effective detection and mitigation mechanisms for such localized or organized attacks without compromising ongoing services.

Innovation Solution

The solution involves determining disjoint network paths using different physical resources, subscribing to analytics functions for attack notifications, and performing proactive attack mitigation through path switching, reconfiguration, or packet dropping based on received information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If trusted Network Functions are used in 5G core networks, then network service reliability is improved, but security vulnerability increases as these trusted NFs can be compromised

Engineering Contradiction:
Improvenetwork service reliabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the network path into multiple disjoint paths between source and destination NFs. When a security threat is detected on one path, traffic can be redirected to alternative paths, isolating the compromised segment while maintaining overall network service reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent establishes multiple disjoint network paths in advance before any security incident occurs. This preliminary preparation enables rapid response to security threats by immediately switching to pre-configured alternative paths without disrupting ongoing services.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If attack detection and mitigation mechanisms are implemented, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a feedback mechanism where the source NF subscribes to security analytics from the analytics function. When attacks or compromised NFs are detected, the analytics function sends notifications back to the source NF, which then automatically switches to alternative paths, creating a closed-loop security response system.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an analytics function as an intermediary between network elements. This intermediary analyzes security data, detects compromised NFs, and provides recommendations, simplifying the overall system architecture by centralizing security intelligence rather than distributing complex detection logic across all NFs.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple disjoint network paths are established, then attack mitigation capability is improved, but network resource consumption increases

Engineering Contradiction:
Improveattack mitigation capabilityVSAvoidnetwork resource consumption
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent establishes multiple disjoint network paths in advance but only activates them when security threats are detected. During normal operation, traffic flows through the primary path, consuming minimal additional resources. The alternative paths remain dormant until needed, providing attack mitigation capability without continuous resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12041455B2Security enhancements for cellular communication systems
Publication Date: 2024.07.16 NOKIA TECHNOLOGIES OY
  • US12041455B2 patent drawing
  • US12041455B2 patent drawing
  • US12041455B2 patent drawing

AI summary

According to an example aspect of the present invention, there is provided a method comprising, determining, by an apparatus configured to operate as a network function a cellular communication system, at least two disjoint network paths, wherein the at least two disjoint network paths are different paths, and comprise different physical resources, transmitting, by the apparatus, a subscription request to an analytics function of the cellular communication system, to request notifications about attacks or risks of attacks on at least one network function on at least one of the at least two disjoint network paths, receiving from the analytics function, by the apparatus, information about at least one compromised network entity and/or at least one network entity having a risk of being compromised on said at least one of the at least two disjoint network paths and performing, by the apparatus, attack mitigation based on said information.