Dynamic Security Resource Allocation for 5G Network Slices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

5G wireless networks introduce new cybersecurity threats due to increased data volumes and vulnerabilities, making conventional security techniques cost-prohibitive and resource-intensive to deploy effectively across diverse networks.

Innovation Solution

A cybersecurity system that monitors and protects Network Functions (NFs) and services within a Service-Based Architecture (SBA) by intercepting network traffic, prioritizing security resources for frequently and recently used NFs, and utilizing a vulnerability-risk threat service to dynamically redirect high-risk data for external collection and sanitization, while also standardizing signaling traffic at Security Edge Protection Proxies (SEPPs) to mitigate cyberattacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security techniques are deployed across diverse 5G networks, then security coverage is improved, but cost and resource consumption become prohibitive

Engineering Contradiction:
Improvesecurity coverageVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent segments security resources and network functions into modular units that can be dynamically allocated. Security functions are divided into discrete components that can be selectively deployed based on risk assessment, allowing comprehensive security coverage without uniformly deploying resources across entire networks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically adjusts security resource allocation based on real-time network conditions, threat levels, and traffic patterns. Security resources are not statically assigned but are instead flexibly distributed to high-risk areas, enabling effective security coverage while minimizing overall resource consumption through adaptive management.

Inventive Principle:
Principle #15Dynamics

2Reliability

If security resources are allocated to all network functions, then security protection is improved, but system complexity and resource efficiency deteriorate

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements local quality by providing differentiated security protection tailored to specific network functions and slices based on their individual risk profiles. Rather than uniform security allocation, each network function receives security resources appropriate to its specific vulnerabilities and importance, reducing overall system complexity while maintaining targeted protection.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

Network functions and slices autonomously assess their own security requirements and request appropriate security resources from the security manager. This self-service mechanism reduces central coordination complexity while ensuring each component receives adequate protection, balancing security effectiveness with system simplicity.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If comprehensive security monitoring is implemented across all network traffic, then threat detection capability is improved, but processing overhead and resource usage increase

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidprocessing overhead
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system implements partial monitoring by focusing security analysis on specific high-risk traffic patterns, network slices, and functions rather than uniformly monitoring all traffic. Security resources are applied excessively only where needed based on risk assessment, achieving high threat detection capability for critical areas while minimizing processing overhead across the entire network.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250106243A1Cybersecurity system for network slices of wireless telecommunications network
Publication Date: 2025.03.27 T MOBILE US INC
  • US20250106243A1 patent drawing
  • US20250106243A1 patent drawing
  • US20250106243A1 patent drawing

AI summary

A method performed by a cybersecurity system that receives a registration request of a wireless device over a 5G network and, in response, selects a network slice associated with a capability, a traffic characteristic, and includes network resources. The system dynamically provisions security resources for multiple network slices based on respective security requirements, which are determined by monitoring network traffic associated with functions or applications supported by the network slices. The system allocates the selected network slice including security resources that satisfy its security requirement to support the wireless device.