MEC Traffic Security Processing via Priority-Based Service Chaining
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In mobile edge computing (MEC) networks, the sequential execution of security functions across multiple security modules leads to increased latency due to repeated packet analysis and processing delays, making it difficult to efficiently manage and prioritize traffic security processing for ultra-low latency and high-speed services.
Innovation Solution
An apparatus and method for traffic security processing in MEC that employs a service chaining model to determine the appropriate security functions and priorities for each packet, using a controller to manage a list of security modules and a main security module to analyze packets and direct them through a sequence of security modules based on priority, minimizing latency and optimizing security engine sequence.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security functions are sequentially executed through multiple security modules, then security coverage is improved, but processing latency increases
Solution Approach 1:
The patent segments the sequential security processing into parallel security function processing units. Each security function (firewall, IPS, DDoS protection, etc.) is divided into independent processing units that can operate simultaneously on different packets or packet segments, transforming the traditional sequential execution model into a parallel architecture that maintains comprehensive security coverage while reducing overall processing latency
Solution Approach 2:
The patent implements preliminary action by performing security function prioritization and packet classification before the actual security processing begins. The system pre-establishes processing paths and assigns priorities to different security functions based on traffic characteristics, allowing high-priority security checks to be executed first without waiting for lower-priority functions, thereby reducing critical path latency while maintaining all security functions
2Measurement precision
If all packets are analyzed by each security module, then security detection accuracy is improved, but processing speed decreases
Solution Approach 1:
The patent applies local quality by implementing differentiated security processing based on packet characteristics and security function priorities. Instead of uniformly analyzing all packets through all security modules, the system assigns different processing depths and security function combinations to different packets based on their type, source, destination, and threat level. High-priority packets receive comprehensive analysis while low-priority packets receive streamlined processing, maintaining detection accuracy for critical threats while improving overall processing speed
Solution Approach 2:
The patent implements partial action by allowing packets to bypass certain low-priority security functions when high-priority security checks have already passed. The system uses a tiered security model where essential security functions (firewall, intrusion detection) are always executed, while additional security functions (application-layer inspection, behavioral analysis) are selectively applied based on packet characteristics, reducing redundant processing while maintaining adequate security coverage
3Reliability
If service chaining is used to route packets through security modules, then security function execution is improved, but packet processing complexity increases
Solution Approach 1:
The patent merges multiple security function routing and packet forwarding operations into a unified parallel processing framework. Instead of using traditional service chaining that requires separate routing decisions and Hop-by-Hop forwarding for each security module, the system combines these functions into integrated processing units that handle multiple security checks in parallel, reducing the number of routing operations and simplifying the overall packet processing architecture
Data Source
AI summary
An apparatus for traffic security processing in a slicing service of mobile edge computing according to an embodiment of the present invention includes: a plurality of security modules for analyzing a received packet to respectively execute security functions suitable for slicing security of mobile edge computing; a controller for managing a slicing security module list in the mobile edge computing; and a main security module for analyzing a received packet on the basis of the slicing security module list to determine a security function to be executed and priority of the security function to be executed, wherein the controller transmits the received packet to at least one corresponding security module among the plurality of security modules according to the priority of the security function to be executed, which is determined by the main security module.


