Network Slice Security Orchestration Across Subnet Instances
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network slicing technologies face challenges in providing secure inter-network slice and intra-network slice communication, as well as preventing attacks at the edge of network slices, which is crucial for mobile network operators and industry verticals.
Innovation Solution
A method and apparatus are provided to enhance security orchestration in a network slice layer by deploying and configuring security function instances in constituent network slice subnet instances, ensuring consistent security policies across domains to prevent network attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network slicing is deployed to provide tailored connectivity for different groups of UEs, then service customization and quality of service are improved, but security vulnerabilities and attack surfaces increase due to shared network infrastructure
Solution Approach 1:
The patent segments the network slice into multiple subnet instances (access network subnet, transport network subnet, core network subnet) and deploys dedicated security function instances at each subnet level. This segmentation allows security policies to be applied granularly to each subnet while maintaining isolation between network slices, thus addressing security vulnerabilities without compromising service customization capabilities
Solution Approach 2:
The patent introduces security function instances as intermediary components between different network subnets and slices. These security functions (firewalls, intrusion detection systems, etc.) act as mediators that filter and monitor traffic flows between subnets and slices, preventing direct exposure of vulnerabilities while maintaining the tailored connectivity that network slicing provides
2Reliability
If security function instances are deployed at the edge of network slice subnets, then attack prevention capability is improved, but system complexity and deployment overhead increase
Solution Approach 1:
The patent designs security function instances with multi-functional capabilities that can operate across different subnet types (access, transport, core) and serve multiple network slices simultaneously. This universal design reduces the number of specialized security components needed, thereby lowering system complexity while maintaining comprehensive attack prevention at the edge of each subnet
Solution Approach 2:
The patent implements a nested deployment architecture where security function instances are embedded within the network slice subnet structure. Security functions are nested at the edge of each subnet instance, which itself is nested within the larger network slice instance. This nested organization provides clear deployment guidelines and reduces operational complexity by establishing hierarchical relationships between security components and network structures
3Manufacturing precision
If differentiated security policies are applied to each constituent network slice subnet instance, then security precision and targeted protection are improved, but policy management complexity and configuration overhead increase
Solution Approach 1:
The patent implements local quality by allowing each network slice subnet instance to have its own customized security policy tailored to its specific requirements and risk profile. Access network subnets can have different policies than core network subnets, and each slice can have differentiated policies within its subnets. This localized policy approach achieves high security precision while the modular architecture manages complexity through clear policy scoping and inheritance mechanisms
Data Source
AI summary
Provided herein are systems and methods for preventing network attacks in a network slice. In particular, security requirements of a network slice instance are retrieved and specific security policies to be applied to each of multiple constituent network slice subnet instances within the network slice instance are identified based on the security requirements. A deployment of one or more security function instances for each subnet instance configured according to a corresponding security policy is then facilitated.


