On-Premise Controller Safety Hatch for Wireless Network Threat Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless communication networks face threats such as denial of service attacks, compromised security tokens, and cryptojacking, which can degrade network performance or disable networks, and these threats can affect not only individual networks but also other tenants in multi-tenant cloud computing environments, leading to cascading communication failures.

Innovation Solution

A 'safety hatch' mechanism is implemented, utilizing rule-based threat detection to temporarily transfer control of wireless networks from cloud-based controllers to on-premise controllers, allowing for localized processing of operational data and monitoring of critical network services, and reverting control once threats are mitigated, thereby minimizing impact and reducing data exposure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If wireless networks use multi-tenant cloud computing environments to house network control functions remotely, then network redundancy and resource efficiency are improved, but vulnerability to cascading communication failures and threats affecting multiple tenants increases

Engineering Contradiction:
Improvenetwork redundancyVSAvoidcascading communication failures
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the network control function into two independent parts: cloud-based controllers providing centralized management and redundancy, and on-premise controllers providing local autonomy. This segmentation allows each part to operate independently, preventing cascading failures from affecting the entire system while maintaining the benefits of cloud-based resource efficiency and redundancy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The on-premise controller acts as an intermediary between the wireless network and the cloud-based controllers. It locally processes operational data and can autonomously respond to threats, mediating between the need for centralized cloud management and the need for local resilience against cascading failures.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If cloud-based controllers are used for remote network control, then operational efficiency and resource utilization are improved, but exposure to threats such as denial of service attacks and compromised security tokens increases

Engineering Contradiction:
Improveoperational efficiencyVSAvoidsecurity against threats
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements local quality by deploying on-premise controllers that provide localized security processing and threat response. These local controllers can independently handle security threats without affecting cloud-based controllers, allowing the system to maintain high operational efficiency through cloud centralization while improving reliability through local security hardening.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The on-premise controllers perform preliminary anti-action by locally detecting and mitigating threats before they can propagate to cloud-based controllers. This preliminary security response prevents compromised security tokens and denial of service attacks from reaching the cloud infrastructure, protecting operational efficiency while enhancing security.

Inventive Principle:
Principle #9Preliminary anti-action

3Ease of operation

If network control functions are centralized in cloud environments, then system complexity is reduced and ease of operation is improved, but the impact of threats on individual networks can affect other tenants

Engineering Contradiction:
Improvecentralized managementVSAvoidcross-tenant threat propagation
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The architecture segments control functions into centralized cloud management for ease of operation and distributed on-premise controllers for threat isolation. This segmentation allows centralized management benefits while preventing cross-tenant threat propagation through local autonomous response capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the security-critical control functions from the centralized cloud environment and places them in on-premise controllers. This extraction removes the vulnerability source from the shared cloud environment, allowing centralized management to continue while eliminating cross-tenant threat propagation risks.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP4154150B1Threat detection and mitigation for remote wireless communication network control systems
Publication Date: 2024.07.10 MOTOROLA SOLUTIONS INC
  • EP4154150B1 patent drawingFigure 1
  • EP4154150B1 patent drawingFigure 2~3
  • EP4154150B1 patent drawingFigure 4

AI summary

Systems and methods for threat detection and mitigation for remote wireless communication network control systems. One example method (300) includes receiving a threat detection message identifying a threat to at least one of a plurality of remote wireless network controllers (112), each associated with one of a plurality of wireless communication networks. The method (300) includes determining a threat rating based on the threat detection message and determining, based on the rating, a threat mitigation action identifying at least a first remote wireless network controller of the plurality of remote wireless network controllers (112). The method (300) includes executing the threat mitigation action by commanding a shift in an operational function of the first remote wireless network controller to a first on-premise wireless network controller associated with the same wireless communication network as the first remote wireless network controller.