On-Demand Security Layer for 5G Network Nodes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

5G wireless networks face increased vulnerabilities due to the large number and diversity of interconnected devices, with a small fraction of IoT and V2X communications posing serious security risks, and conventional network hardening techniques are cost-prohibitive and impractical for deployment across a diverse network of devices.

Innovation Solution

A dynamic security layer that intelligently deploys security resources only when needed, leveraging a 'bait and switch' technique to simulate vulnerabilities and quarantine unauthorized intrusions, and a software-defined security service that turns on-demand during runtime execution to safeguard the network infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional network hardening techniques are deployed across all devices, then network security is improved, but deployment cost and resource consumption increase significantly

Engineering Contradiction:
Improvenetwork securityVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by implementing security resources selectively at specific network locations (cell sites with elevated risk levels) rather than uniformly across all devices. The system dynamically identifies and hardens only the vulnerable cell sites that require protection, leaving other areas with nominal risk levels unchanged. This resolves the contradiction by maintaining network security at critical points while avoiding the excessive complexity and cost of universal deployment.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements dynamics through continuous monitoring of risk levels at different cell sites and dynamic adjustment of security resource allocation. The system can activate or deactivate security resources based on changing threat conditions, transforming the static network hardening approach into a flexible, adaptive system. This resolves the contradiction by ensuring security is applied only when and where needed, reducing overall deployment complexity while maintaining reliability.

Inventive Principle:
Principle #15Dynamics

2Reliability

If security resources are allocated to all cell sites, then network security coverage is improved, but network performance degrades due to resource overhead

Engineering Contradiction:
Improvesecurity coverageVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial action by allocating security resources to only a subset of cell sites that have elevated risk levels, rather than providing full security coverage across all sites. The system monitors risk levels and activates security resources only where necessary, providing sufficient security coverage for vulnerable areas while avoiding the performance degradation that would result from universal resource allocation.

Inventive Principle:
Principle #16Partial or excessive action

3Loss of energy

If security resources are dynamically provisioned on-demand, then resource efficiency is improved, but response time to security threats increases

Engineering Contradiction:
Improveresource efficiencyVSAvoidsecurity response time
Core Design Contradiction:
Loss of energyVSLoss of time

Solution Approach 1:

The patent applies preliminary action by continuously monitoring risk levels and maintaining readiness to deploy security resources at cell sites. The system proactively identifies elevated risk conditions and prepares security resources for deployment before actual threats materialize. This resolves the contradiction by ensuring rapid response capability when threats are detected while maintaining resource efficiency during normal operations through selective activation only when risk levels indicate potential vulnerabilities.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11533624B2On-demand security for network resources or nodes, such as for a wireless 5G network
Publication Date: 2022.12.20 T MOBILE US INC
  • US11533624B2 patent drawing
  • US11533624B2 patent drawing
  • US11533624B2 patent drawing

AI summary

The disclosed embodiments include a method performed by a network access node to thwart unauthorized activity on a network such as a 5G wireless network. For example, the method can include employing contextual information to determine risk to the 5G wireless network. A network access node can detect that a wireless device seeks to perform unauthorized activity, and then implements security measures such that the unauthorized activity is thwarted at the network access node.