MEC Traffic Security Processing via Priority-Based Service Chaining

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In mobile edge computing (MEC) networks, the sequential execution of security functions across multiple security modules leads to increased latency due to repeated packet analysis and processing delays, making it difficult to efficiently manage and prioritize traffic security processing for ultra-low latency and high-speed services.

Innovation Solution

An apparatus and method for traffic security processing in MEC that employs a service chaining model to determine the appropriate security functions and priorities for each packet, using a controller to manage a list of security modules and a main security module to analyze packets and direct them through a sequence of security modules based on priority, minimizing latency and optimizing security engine sequence.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security functions are sequentially executed through multiple security modules, then security coverage is improved, but processing latency increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidprocessing latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the sequential security processing into parallel security function processing units. Each security function (firewall, IPS, DDoS protection, etc.) is divided into independent processing units that can operate simultaneously on different packets or packet segments, transforming the traditional sequential execution model into a parallel architecture that maintains comprehensive security coverage while reducing overall processing latency

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by performing security function prioritization and packet classification before the actual security processing begins. The system pre-establishes processing paths and assigns priorities to different security functions based on traffic characteristics, allowing high-priority security checks to be executed first without waiting for lower-priority functions, thereby reducing critical path latency while maintaining all security functions

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If all packets are analyzed by each security module, then security detection accuracy is improved, but processing speed decreases

Engineering Contradiction:
Improvesecurity detection accuracyVSAvoidprocessing speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent applies local quality by implementing differentiated security processing based on packet characteristics and security function priorities. Instead of uniformly analyzing all packets through all security modules, the system assigns different processing depths and security function combinations to different packets based on their type, source, destination, and threat level. High-priority packets receive comprehensive analysis while low-priority packets receive streamlined processing, maintaining detection accuracy for critical threats while improving overall processing speed

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial action by allowing packets to bypass certain low-priority security functions when high-priority security checks have already passed. The system uses a tiered security model where essential security functions (firewall, intrusion detection) are always executed, while additional security functions (application-layer inspection, behavioral analysis) are selectively applied based on packet characteristics, reducing redundant processing while maintaining adequate security coverage

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If service chaining is used to route packets through security modules, then security function execution is improved, but packet processing complexity increases

Engineering Contradiction:
Improvesecurity function executionVSAvoidpacket processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple security function routing and packet forwarding operations into a unified parallel processing framework. Instead of using traditional service chaining that requires separate routing decisions and Hop-by-Hop forwarding for each security module, the system combines these functions into integrated processing units that handle multiple security checks in parallel, reducing the number of routing operations and simplifying the overall packet processing architecture

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11991522B2Apparatus and method for traffic security processing in 5G mobile edge computing slicing service
Publication Date: 2024.05.21 WINS CO LTD
  • US11991522B2 patent drawing
  • US11991522B2 patent drawing
  • US11991522B2 patent drawing

AI summary

An apparatus for traffic security processing in a slicing service of mobile edge computing according to an embodiment of the present invention includes: a plurality of security modules for analyzing a received packet to respectively execute security functions suitable for slicing security of mobile edge computing; a controller for managing a slicing security module list in the mobile edge computing; and a main security module for analyzing a received packet on the basis of the slicing security module list to determine a security function to be executed and priority of the security function to be executed, wherein the controller transmits the received packet to at least one corresponding security module among the plurality of security modules according to the priority of the security function to be executed, which is determined by the main security module.