Message Bus Controller for 5G Core Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The 5G cellular network faces limited protection against device-on-device attacks, as existing security measures have primarily focused on Internet and carrier network threats, leaving vulnerabilities in device security and scalability.
Innovation Solution
Implementing a message bus controller within the 5G core network to monitor and analyze messages for potential threats, including DDoS attacks, by subscribing to all messages and performing context-based and non-context-based analyses to identify abnormal behavior or overload, thereby restricting or dropping malicious messages.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network security measures focus only on Internet and carrier network threats, then existing security infrastructure is maintained, but device-on-device attacks remain unprotected
Solution Approach 1:
The patent introduces a message bus controller as an intermediary component between network elements and the message bus. This controller monitors, analyzes, and controls messages in real-time, acting as a security gateway that detects device-on-device attacks without requiring changes to existing network elements or devices. The intermediary approach allows security enhancement while maintaining compatibility with existing infrastructure.
2Measurement precision
If a message bus controller monitors all messages for security threats, then detection capability is improved, but message processing overhead increases
Solution Approach 1:
The message bus controller implements partial monitoring by focusing analysis on specific message types, patterns, and contexts that are more likely to indicate threats. Rather than analyzing every message in detail, the controller uses heuristics and rules to identify suspicious messages for deeper inspection, reducing overall processing overhead while maintaining effective threat detection.
Solution Approach 2:
The controller performs continuous monitoring and analysis of message flow without interrupting the normal operation of the message bus. By operating in real-time and using efficient analysis techniques, the system maintains security surveillance while minimizing impact on message processing speed and network performance.
3Reliability
If the message bus controller restricts message flow to protect sensitive elements, then network protection is improved, but message delivery efficiency decreases
Solution Approach 1:
The message bus controller dynamically adjusts message flow restrictions based on real-time security conditions and network state. Rather than applying static blocking rules, the controller adapts its filtering and rate-limiting behavior according to detected threats, normal traffic patterns, and network load, optimizing both security protection and message delivery efficiency under different operating conditions.
Data Source
AI summary
Using a message bus controller to protect 5G core elements can include accessing, by a computing device that executes a message bus controller, a message in a message bus of a packet core of a cellular network. The message can be generated by a first network function and transmitted to a second network function via the message bus, wherein the second network function can subscribe to messages from the first network function. The computing device can determine if delivery of the message to the second network function should be restricted. If so, the computing device can drop the message, and if not, the computing device can allow a message flow associated with the message to resume.


