Private Cellular Network Slicing for Secure IoT Remote Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IoT and IIoT networks face challenges in securely allowing remote access to endpoint devices due to security risks from unfettered Internet access, which can lead to malicious attacks and data exfiltration, and current VPN configurations are cumbersome to manage as the number of devices increases.
Innovation Solution
The implementation of 5G network slicing and user plane functions to create a secure remote access function (SRAF) that configures a dedicated network slice for secure communication between endpoint devices and remote clients, using virtual private network tunnels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If endpoint devices are allowed to access the Internet freely to enable remote access and IoT functionality, then remote access capability is improved, but security risk increases due to potential malicious attacks and data exfiltration
Solution Approach 1:
The patent segments the cellular network into multiple network slices, with dedicated slices for remote access traffic versus other Internet traffic. This segmentation allows remote access functionality while isolating it from general Internet security risks, thereby maintaining ease of operation while reducing security exposure.
Solution Approach 2:
The patent introduces a remote access function (RAF) as an intermediary component within the cellular network that mediates between endpoint devices and remote clients. This intermediary enables secure remote access by controlling and monitoring traffic flow, allowing remote access capability while mitigating security risks through centralized management.
2Object-affected harmful factors
If traditional VPN configurations are used to secure remote access, then security is improved, but device complexity and management overhead increase as the number of devices scales
Solution Approach 1:
The patent moves the security management from the endpoint device level to the network level by implementing security functions within the cellular network infrastructure. This dimensional shift allows security to be enforced centrally through network slicing and RAF functions, reducing the complexity and management overhead at individual devices while maintaining strong security.
Solution Approach 2:
The patent creates a universal remote access solution where the cellular network infrastructure provides security and access management services to all endpoint devices through standardized network slices and RAF functions. This multi-functional approach serves multiple devices simultaneously through a single centralized mechanism, reducing overall system complexity compared to individual VPN configurations for each device.
3Object-affected harmful factors
If dedicated secure connections are established for each remote access request, then security is improved, but network complexity and resource consumption increase
Solution Approach 1:
The patent segments the network into reusable network slices that can be shared across multiple remote access requests. Instead of creating entirely separate connections for each request, the same secured network slice can serve multiple clients and endpoints, maintaining security through isolation while reducing overall network complexity and resource consumption through sharing.
Solution Approach 2:
The patent implements dynamic allocation of network slice resources where the same network slice infrastructure can dynamically serve different remote access requests as needed. This dynamic approach allows secure connections to be established on-demand while reusing underlying network resources, reducing complexity compared to static dedicated connections for each request.
Data Source
AI summary
In one embodiment, a device receives a request from a client to remotely access an endpoint in a local network. The device instantiates a network slice having a remote access function in a cellular network. The device causes the endpoint to communicate a particular type of traffic via the network slice and the remote access function. The device configures a virtual private network tunnel between the client and the remote access function. The client and endpoint communicate with one another via a connection that comprises the network slice and the virtual private network tunnel.


