On-Demand Wireless Device Security for 5G Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

5G wireless networks face vulnerabilities due to a small fraction of IoT and V2X communications posing security risks, and unsecured rural area networks, which conventional network hardening techniques are unable to address effectively due to cost and resource intensiveness.

Innovation Solution

A dynamic security layer that intelligently deploys security resources only to risky portions of the network on-demand, leveraging existing resources and employing software-defined security services, self-cleaning functions, and wireless device-centric security solutions to mitigate risks transparently to customers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional network hardening techniques are deployed across the entire 5G network, then security coverage is improved, but cost and resource consumption increase significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidsecurity resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent implements security resources selectively at specific network locations rather than uniformly across the entire network. Security functions are deployed locally at network access nodes where risks are detected, concentrating security resources in high-risk areas while leaving low-risk areas with minimal security overhead, thus resolving the contradiction between comprehensive security coverage and resource consumption

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent employs dynamic security resource allocation that adapts to changing network conditions and detected risks. Security resources are activated on-demand based on real-time risk assessment, allowing the system to scale security capacity dynamically rather than maintaining static high-level security everywhere, thereby reducing overall resource consumption while maintaining reliability

Inventive Principle:
Principle #15Dynamics

2Quantity of substance

If security resources are deployed on-demand to risky portions of the network, then resource efficiency is improved, but security response time may be delayed

Engineering Contradiction:
Improvesecurity resourcesVSAvoidsecurity response time
Core Design Contradiction:
Quantity of substanceVSLoss of time

Solution Approach 1:

The patent pre-deploys security capabilities at network access nodes in a dormant or ready state before threats are detected. This preliminary positioning of security resources ensures that when risks are identified, the security functions can be activated immediately without requiring resource allocation or deployment time, thus maintaining fast response times while keeping actual resource consumption low until needed

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements continuous monitoring and risk assessment mechanisms that provide real-time feedback about network security conditions. This feedback loop enables the system to detect risks early and trigger on-demand security resource deployment promptly, minimizing the time delay between threat emergence and security response while optimizing resource allocation based on actual risk levels

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11444980B2On-demand wireless device centric security for a 5G wireless network
Publication Date: 2022.09.13 T MOBILE US INC
  • US11444980B2 patent drawing
  • US11444980B2 patent drawing
  • US11444980B2 patent drawing

AI summary

The disclosed embodiments include a method performed by a wireless network to mitigate a security risk arising from an application-layer transaction and contextual scenario of a wireless device (WD). A security resource can be maintained inactive by default and configured for on-demand activation in response to a security risk associated with the WD. The method can include monitoring the WD for application-layer transactions and contextual scenarios, and detecting a security risk relative to a particular type of a application-layer transaction and a contextual scenario of the WD. In response to detecting the security risk, the security resource is activated to support the application-layer transaction while safeguarding the entire wireless network. In response to detecting a change to the application-layer transaction or the particular contextual scenario, the security resource for the WD can be deactivated.