Dynamic Security Resource Allocation for 5G Network Slices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
5G wireless networks introduce new cybersecurity threats due to increased data volumes and vulnerabilities, making conventional security techniques cost-prohibitive and resource-intensive to deploy effectively across diverse networks.
Innovation Solution
A cybersecurity system that monitors and protects Network Functions (NFs) and services within a Service-Based Architecture (SBA) by intercepting network traffic, prioritizing security resources for frequently and recently used NFs, and utilizing a vulnerability-risk threat service to dynamically redirect high-risk data for external collection and sanitization, while also standardizing signaling traffic at Security Edge Protection Proxies (SEPPs) to mitigate cyberattacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional security techniques are deployed across diverse 5G networks, then security coverage is improved, but cost and resource consumption become prohibitive
Solution Approach 1:
The patent segments security resources and network functions into modular units that can be dynamically allocated. Security functions are divided into discrete components that can be selectively deployed based on risk assessment, allowing comprehensive security coverage without uniformly deploying resources across entire networks.
Solution Approach 2:
The system dynamically adjusts security resource allocation based on real-time network conditions, threat levels, and traffic patterns. Security resources are not statically assigned but are instead flexibly distributed to high-risk areas, enabling effective security coverage while minimizing overall resource consumption through adaptive management.
2Reliability
If security resources are allocated to all network functions, then security protection is improved, but system complexity and resource efficiency deteriorate
Solution Approach 1:
The patent implements local quality by providing differentiated security protection tailored to specific network functions and slices based on their individual risk profiles. Rather than uniform security allocation, each network function receives security resources appropriate to its specific vulnerabilities and importance, reducing overall system complexity while maintaining targeted protection.
Solution Approach 2:
Network functions and slices autonomously assess their own security requirements and request appropriate security resources from the security manager. This self-service mechanism reduces central coordination complexity while ensuring each component receives adequate protection, balancing security effectiveness with system simplicity.
3Measurement precision
If comprehensive security monitoring is implemented across all network traffic, then threat detection capability is improved, but processing overhead and resource usage increase
Solution Approach 1:
The system implements partial monitoring by focusing security analysis on specific high-risk traffic patterns, network slices, and functions rather than uniformly monitoring all traffic. Security resources are applied excessively only where needed based on risk assessment, achieving high threat detection capability for critical areas while minimizing processing overhead across the entire network.
Data Source
AI summary
A method performed by a cybersecurity system that receives a registration request of a wireless device over a 5G network and, in response, selects a network slice associated with a capability, a traffic characteristic, and includes network resources. The system dynamically provisions security resources for multiple network slices based on respective security requirements, which are determined by monitoring network traffic associated with functions or applications supported by the network slices. The system allocates the selected network slice including security resources that satisfy its security requirement to support the wireless device.


