Dynamic Security Layer for 5G Network Slices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
5G wireless networks face vulnerabilities due to a small fraction of IoT and V2X communications posing security risks, and unsecured rural area networks, which conventional network hardening techniques are unable to address effectively due to cost and resource intensiveness.
Innovation Solution
A dynamic security layer that intelligently deploys security resources only to risky portions of the network on-demand, leveraging existing resources and using software-defined security services, self-cleaning functions, and wireless device-centric security solutions to mitigate risks without uniformly burdening the entire network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional network hardening techniques are deployed across the entire 5G network, then network security is improved, but deployment cost and resource consumption become prohibitively high
Solution Approach 1:
The patent applies local quality by deploying security resources selectively to specific network slices rather than uniformly across the entire network. The security layer is instantiated only in slices identified as high-risk (e.g., IoT, V2X, mobile broadcast), allowing differentiated security protection where needed while leaving low-risk slices with standard protection, thereby reducing overall resource consumption while maintaining network security.
Solution Approach 2:
The patent segments the 5G network into multiple network slices, each with different security requirements and risk profiles. By dividing the network into separable slices (IoT, V2X, mobile broadband, mobile broadcast), the system can apply security hardening only to vulnerable slices rather than the entire network, reducing the quantity of security resources needed while maintaining protection where necessary.
2Reliability
If security resources are deployed uniformly across all network slices, then network security coverage is improved, but network performance and user experience deteriorate due to resource burden
Solution Approach 1:
The patent implements dynamic security resource allocation where the security layer is instantiated or deactivated based on real-time risk assessment of each network slice. The system continuously monitors slice characteristics and security threats, dynamically adjusting security resource deployment to match actual needs, thereby maintaining security coverage where required while preserving network performance in low-risk areas.
Solution Approach 2:
The patent applies local quality by providing enhanced security protection only to specific network slices identified as high-risk (IoT, V2X, mobile broadcast), while leaving other slices with standard security measures. This localized approach ensures adequate security coverage for vulnerable slices without imposing unnecessary resource burdens on the entire network, thus maintaining overall network performance and user experience.
3Measurement precision
If comprehensive security monitoring is implemented across all device types, then detection accuracy is improved, but system complexity and resource requirements increase
Solution Approach 1:
The patent segments security monitoring by network slice type, implementing specialized monitoring approaches for each slice category (IoT, V2X, mobile broadcast, mobile broadband). This segmented monitoring strategy improves detection accuracy for each specific slice type by applying tailored security checks while avoiding the need for a single complex universal monitoring system, thereby reducing overall system complexity.
Data Source
AI summary
The disclosed embodiments include a method performed by a wireless network to dynamically provision security resources during runtime execution of a service environment. The security resources are distributed across cell sites that provide coverage areas for multiple wireless devices (WDs) in multiple service environments. The cell sites are monitored during runtime execution of the multiple service environments to detect risk levels that indicate a vulnerability to the wireless network. When an elevated risk level is detected for a particular cell site, security resources of the security layer are dynamically provisioned for the particular cell site to safeguard the entire wireless network. Hence, the provisioned security resources can include a security resource from a different cell site.


