Network Slice Security Orchestration Across Subnet Instances

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network slicing technologies face challenges in providing secure inter-network slice and intra-network slice communication, as well as preventing attacks at the edge of network slices, which is crucial for mobile network operators and industry verticals.

Innovation Solution

A method and apparatus are provided to enhance security orchestration in a network slice layer by deploying and configuring security function instances in constituent network slice subnet instances, ensuring consistent security policies across domains to prevent network attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network slicing is deployed to provide tailored connectivity for different groups of UEs, then service customization and quality of service are improved, but security vulnerabilities and attack surfaces increase due to shared network infrastructure

Engineering Contradiction:
Improveservice customizationVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the network slice into multiple subnet instances (access network subnet, transport network subnet, core network subnet) and deploys dedicated security function instances at each subnet level. This segmentation allows security policies to be applied granularly to each subnet while maintaining isolation between network slices, thus addressing security vulnerabilities without compromising service customization capabilities

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces security function instances as intermediary components between different network subnets and slices. These security functions (firewalls, intrusion detection systems, etc.) act as mediators that filter and monitor traffic flows between subnets and slices, preventing direct exposure of vulnerabilities while maintaining the tailored connectivity that network slicing provides

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security function instances are deployed at the edge of network slice subnets, then attack prevention capability is improved, but system complexity and deployment overhead increase

Engineering Contradiction:
Improveattack prevention capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent designs security function instances with multi-functional capabilities that can operate across different subnet types (access, transport, core) and serve multiple network slices simultaneously. This universal design reduces the number of specialized security components needed, thereby lowering system complexity while maintaining comprehensive attack prevention at the edge of each subnet

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements a nested deployment architecture where security function instances are embedded within the network slice subnet structure. Security functions are nested at the edge of each subnet instance, which itself is nested within the larger network slice instance. This nested organization provides clear deployment guidelines and reduces operational complexity by establishing hierarchical relationships between security components and network structures

Inventive Principle:
Principle #7Nested doll (Nesting)

3Manufacturing precision

If differentiated security policies are applied to each constituent network slice subnet instance, then security precision and targeted protection are improved, but policy management complexity and configuration overhead increase

Engineering Contradiction:
Improvesecurity precisionVSAvoidpolicy management complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent implements local quality by allowing each network slice subnet instance to have its own customized security policy tailored to its specific requirements and risk profile. Access network subnets can have different policies than core network subnets, and each slice can have differentiated policies within its subnets. This localized policy approach achieves high security precision while the modular architecture manages complexity through clear policy scoping and inheritance mechanisms

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12413487B2Method and apparatus for preventing network attacks in a network slice
Publication Date: 2025.09.09 NOKIA TECHNOLOGIES OY
  • US12413487B2 patent drawing
  • US12413487B2 patent drawing
  • US12413487B2 patent drawing

AI summary

Provided herein are systems and methods for preventing network attacks in a network slice. In particular, security requirements of a network slice instance are retrieved and specific security policies to be applied to each of multiple constituent network slice subnet instances within the network slice instance are identified based on the security requirements. A deployment of one or more security function instances for each subnet instance configured according to a corresponding security policy is then facilitated.