EPC Guard Agents for Core Network Integrity Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies lack effective mechanisms to detect and mitigate advanced persistent threats (APTs) in core network elements, leading to potential unauthorized access and data integrity issues.
Innovation Solution
The EPC Guard system, which includes EPC guard agents residing in network elements, queries a master EPC guard (MEG) to verify the integrity of network elements by comparing cryptographic values, thereby detecting any unauthorized changes or threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If no security verification mechanism is implemented, then network operations are simple and fast, but security threats such as APTs can compromise network integrity
Solution Approach 1:
A security verification device is introduced as an intermediary component between core network elements. This device receives verification requests from network elements, performs security checks, and returns verification results. The intermediary approach allows security verification to be centralized and managed separately from the core network operations, improving security without significantly complicating the network elements themselves.
Solution Approach 2:
The system performs security verification in advance before allowing network operations to proceed. By checking the authenticity and integrity of network elements beforehand, the system prevents security threats from compromising network operations, thereby improving reliability without adding complexity to the operational flow.
2Reliability
If security verification is performed for every network element, then threat detection capability is improved, but processing time and operational efficiency decrease
Solution Approach 1:
Security verification is performed as a preliminary action before network elements begin their operations. By completing verification beforehand, the system ensures that only authenticated and integrity-checked elements proceed to network operations, maintaining high threat detection capability without slowing down actual network processing.
Solution Approach 2:
The security verification device provides feedback to network elements about their authentication status. This feedback mechanism allows network elements to proceed with operations once verified, maintaining efficient network operation while ensuring thorough security checks have been performed.
3Reliability
If cryptographic value comparison is implemented, then network element authenticity is verified, but computational resources are consumed
Solution Approach 1:
The security verification device acts as an intermediary that handles the computationally intensive cryptographic comparisons separately from the core network elements. This allows integrity verification to be performed using strong cryptographic methods without consuming the computational resources of the network elements themselves, maintaining both verification reliability and resource efficiency.
Data Source
AI summary
When a network element attempts to establish a session with another network element, a security verification agent may be activated in one or both network elements. The security verification agents, such as front-end processors, virtual network functions, or other software agents, may reside in each of the network elements.


