Global Event ID Mapping for Cross-Vendor Cellular Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile communication event identifiers (IDs) are non-standardized and proprietary across different network function (NF) vendors, hindering visibility into and comprehensive analysis of mobile communication events, especially for cybersecurity event detection.
Innovation Solution
Implementing global mobile communication event identifiers that are unique to a category of events and consistent across NFs, enabling standardized logging and correlation of events across different vendors, allowing for comprehensive cybersecurity event detection and response.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If proprietary event IDs are used by each NF vendor, then vendor-specific optimizations and algorithms can be maintained, but visibility into and comprehensive view of mobile communication events across the network is lost
Solution Approach 1:
The patent introduces a standardized event identifier mapping mechanism that acts as an intermediary between proprietary vendor event IDs and a unified global event ID system. This mapping layer allows different NF vendors to maintain their proprietary internal event ID schemes while translating them into a common standardized format for network-wide visibility and correlation, thus resolving the contradiction between vendor-specific optimizations and comprehensive event visibility
Solution Approach 2:
The patent implements a universal global event ID system that serves multiple functions: it provides standardized identification across all NF vendors, enables network-wide event correlation, supports cybersecurity threat detection, and maintains compatibility with proprietary vendor systems through mapping mechanisms. This multi-functional approach allows the system to achieve both vendor-specific customization and network-wide standardization simultaneously
2Ease of manufacture
If proprietary event IDs are used in event logs, then each NF can record events according to its own schema, but correlation of events across different NFs and vendors becomes difficult
Solution Approach 1:
The patent employs a standardized event identifier mapping mechanism as an intermediary that translates proprietary NF-specific event IDs into a unified global event ID schema. This allows each NF to continue implementing logging according to its own schema and ease of manufacture requirements, while the mapping layer enables straightforward correlation of events across different NFs without increasing overall system complexity
Solution Approach 2:
The patent segments the event identification system into two independent parts: the proprietary event ID schema maintained by each NF for local logging simplicity, and the standardized global event ID system for network-wide correlation. This segmentation allows each part to be optimized independently - NFs can use simple proprietary schemas for local logging while the standardized layer handles the complexity of cross-NF correlation
3Reliability
If standardized global event IDs are implemented, then network-wide event correlation and cybersecurity detection are improved, but compatibility with existing proprietary NF systems must be maintained
Solution Approach 1:
The patent introduces a standardized event identifier mapping mechanism that serves as an intermediary between existing proprietary NF systems and the new standardized global event ID system. This mapping layer translates proprietary event IDs into standardized formats, enabling reliable cybersecurity event detection across the network while maintaining full compatibility with existing proprietary NF systems without requiring changes to their internal structures
Solution Approach 2:
The patent implements a universal standardized event ID system that performs multiple functions simultaneously: it enables network-wide event correlation for cybersecurity detection, maintains compatibility with proprietary vendor systems through mapping, provides standardized logging across all NFs, and supports both current and future NF implementations. This multi-functionality allows the system to achieve improved reliability without sacrificing adaptability
Data Source
AI summary
Global mobile communication event identifiers (IDs) improve security by enabling early detection of cybersecurity events in cellular networks. The event IDs are each unique to a category of mobile communication events and consistent across the network functions (NF), even from different vendors. NFs assign event IDs to mobile communication events, which are reported to a cybersecurity operations center. The cybersecurity operations center has visibility into network-wide events and is thus able to match occurrences of event IDs with categorized attacks, when an attack is occurring. This enables rapid, intelligent selection of a defensive response.


