Personal Virtual Core Networks for Proactive Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern mobility networks are vulnerable to various attacks, including DoS and DDoS, call-forwarding attacks, and man-in-the-middle attacks, which existing reactive approaches like software-defined networks fail to prevent effectively, instead only reacting to attacks by scaling resources.

Innovation Solution

Implementing personal virtual core networks that monitor user devices for malicious activity, isolate threats, and create virtual core networks to secure communications, allowing for proactive defense against attacks by isolating user devices and rerouting communications through a dedicated virtual network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software defined networks are used to scale resources elastically in response to attacks, then network capacity can be increased to satisfy inflated demand, but the root problem of preventing attacks is not solved and the approach is merely reactive

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network into multiple virtual core networks, each serving specific users or groups. This segmentation allows isolated containment of attacks within individual virtual networks, preventing them from affecting the entire network infrastructure. Each virtual core network can be independently managed, secured, and scaled without impacting others.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary actions by pre-configuring virtual core networks and establishing security policies before attacks occur. The system proactively monitors user behavior and device characteristics to identify potential threats in advance, creating isolated virtual environments ready to contain suspicious activity before it can spread.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If reactive resource scaling is implemented to respond to launched attacks, then additional capacity can be provided to satisfy artificial demand, but attacks are not prevented from being launched in the first place

Engineering Contradiction:
Improvenetwork response capabilityVSAvoidattack prevention
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary actions by establishing virtual core networks and security monitoring mechanisms before attacks occur. User behavior analytics and device monitoring are continuously active to detect potential threats in advance, enabling proactive isolation of malicious devices before they can launch attacks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces virtual core networks as intermediary layers between users and the core network infrastructure. This intermediary layer provides a buffer that can isolate and contain malicious activity, preventing direct attacks on the core network while maintaining service continuity through controlled access.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If user devices are monitored and isolated based on threat identification, then network security can be enhanced by preventing malicious activity, but additional complexity is introduced in monitoring and isolation mechanisms

Engineering Contradiction:
Improvenetwork securityVSAvoidmonitoring system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal monitoring framework that collects and analyzes multiple types of data (user behavior, device characteristics, network traffic patterns) through a single integrated system. The virtual core network infrastructure provides multi-functional capabilities, serving both as a service delivery mechanism and as an isolation container for threats, reducing the need for separate specialized systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9526024B2Personal virtual core networks
Publication Date: 2016.12.20 AT&T INTELLECTUAL PROPERTY I L P
  • US9526024B2 patent drawing
  • US9526024B2 patent drawing
  • US9526024B2 patent drawing

AI summary

Concepts and technologies are disclosed herein for personal virtual core networks. A processor executing a network access service can determine if the user device should be isolated from a core network that provides devices at a location with connectivity. If the processor determines that the user device should be isolated, the processor can identify resources supporting the connectivity. The resources can include network resources and the core network. The processor can create a virtual core network to support the connectivity, and activate the virtual core network.