Network Orchestrator Security Context Provisioning for Core Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless cellular networks, particularly 5G networks, lack robust security measures to prevent rogue network nodes from gaining access to the core network, leading to potential harmful operations such as service degradation and Denial-of-Service attacks, without adequate provisioning of secure protocols.

Innovation Solution

Implementing a network orchestrator that automates the creation of secure communication tunnels and provisions security contexts through network slicing, using protocols like TLS, DTLS, and IPsec, along with post-quantum resistant algorithms, to establish secure communication channels between network functions and radio access nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional wireless cellular network architecture is used, then network functionality and service coverage are maintained, but security vulnerabilities exist allowing rogue network nodes to access the core network and perform harmful operations

Engineering Contradiction:
Improvenetwork securityVSAvoidunauthorized access and malicious operations
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the network architecture by introducing network slicing that creates isolated virtual networks. Each slice is separated by virtualization layers, preventing rogue nodes in one slice from accessing other slices or the core network. The service communication proxy further segments communication paths by intercepting and validating service requests between network functions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces service communication proxy as an intermediary component between network functions. This proxy validates service requests, checks authentication credentials, and mediates communication traffic. The intermediary prevents direct unauthorized access to core network functions by all traffic through centralized security validation points.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security protocols are added to protect against rogue network nodes, then network security is improved, but system complexity and implementation difficulty increase

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The service communication proxy serves multiple functions: authentication validation, service request routing, security policy enforcement, and traffic monitoring. This multi-functional component consolidates what would otherwise require multiple separate security systems, reducing overall system complexity while maintaining comprehensive security protection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements preliminary security validation through the service communication proxy before traffic reaches core network functions. Authentication credentials are verified in advance, and service requests are pre-authenticated. This preliminary action prevents unauthorized access attempts from reaching vulnerable core functions, simplifying the security architecture by handling validation centrally rather than at each individual function.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250293852A1Security in networks
Publication Date: 2025.09.18 T MOBILE US INC
  • US20250293852A1 patent drawing
  • US20250293852A1 patent drawing
  • US20250293852A1 patent drawing

AI summary

Techniques related to providing secure communications in a network are disclosed. In one example, an alternative for providing secure communication in an automated way in a network including retrieving by a network server configured to manage one or more network nodes in the network a security certificate and other security configuration corresponding to a network node. Transmitted, by the network server, including pair(s) of public and private keys and other parameters to the network node to enable the network node to establish a secure communication channel with at least another network node.