Multi-Dimensional DNS for 5G Threat Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

5G wireless networks face increased cybersecurity threats due to higher volumes and types of data, creating vulnerabilities that conventional security techniques are unable to effectively address, especially given the cost and resource intensiveness of deploying security resources across diverse networks.

Innovation Solution

A multi-dimensional Domain Name System (DNS) and digital on-demand coupons are used to provide personalized protection for network entities by mapping cybersecurity threats to IP addresses or URLs, allowing for targeted and dynamic deployment of security resources based on risk levels and contextual information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security techniques are deployed across diverse networks, then security coverage is improved, but cost and resource consumption increase significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent implements risk-based security where different security measures are applied to different network entities based on their specific risk levels. High-risk entities receive intensive security resources while low-risk entities receive minimal protection, optimizing resource allocation across the network

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts security resource allocation based on real-time risk assessments. Security posture changes automatically as network conditions, threats, and entity vulnerabilities evolve, ensuring resources are deployed only when and where needed

Inventive Principle:
Principle #15Dynamics

2Reliability

If security resources are deployed across all network entities, then protection comprehensiveness is improved, but deployment complexity increases

Engineering Contradiction:
Improveprotection comprehensivenessVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network into risk-based groups and applies differentiated security policies to each segment. This modular approach simplifies deployment by allowing security configurations to be tailored to specific risk categories rather than implemented uniformly across all entities

Inventive Principle:
Principle #1Segmentation

3Loss of time

If real-time threat detection is implemented, then response time is improved, but system complexity increases

Engineering Contradiction:
Improveresponse timeVSAvoidsystem complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The system performs preliminary risk assessments and establishes baseline security postures before threats materialize. By pre-configuring security parameters and conducting advance risk evaluations, the system enables rapid real-time response without the full complexity of continuous real-time analysis

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12074899B2Network security system including a multi-dimensional domain name system to protect against cybersecurity threats
Publication Date: 2024.08.27 T MOBILE US INC
  • US12074899B2 patent drawing
  • US12074899B2 patent drawing
  • US12074899B2 patent drawing

AI summary

A method performed by a security system that can analyze a vulnerability or a risk applicable to a network entity to identify a cybersecurity threat and associated risk level. The security system can store indications of cybersecurity threats and risk levels in a database of a Domain Name System (DNS). The security system can monitor and resolve network traffic to determine IP addresses or URLs associated with the cybersecurity threats. The security system stores a map of the cybersecurity threats and IP addresses or URLs such that the security system can protect a network entity by processing network traffic to sources or destinations of network traffic that can harm particular network entities, and execute personalized security procedures to protect the network entities.