Software Defined Perimeter Controller for 5G Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Advanced telecommunications networks, particularly those using SDN architecture in 5G/6G environments, face significant cybersecurity threats due to increased device connectivity, third-party entity vulnerabilities, and the adoption of IoT devices and cloud computing, which can expose private user information to cyber-attacks.

Innovation Solution

Integration of a Software Defined Perimeter (SDP) for network applications in 5G/6G telecommunications networks, which involves an SDP controller managing connection initiation and acceptance through a control channel, establishing a secure tunnel for data flow moderation between user equipment and microservices, and using a VPN for authentication requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If SDN architecture is adopted to enable flexible deployment and automated provisioning, then network adaptability and ease of operation are improved, but network security and vulnerability to cyber-attacks worsen

Engineering Contradiction:
Improvenetwork adaptabilityVSAvoidcyber-security threats
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a Software Defined Perimeter (SDP) controller as an intermediary component between the SDN controller and network resources. This SDP controller acts as a mediator that establishes secure, encrypted tunnels for all communications, preventing direct exposure of network infrastructure to external threats while maintaining the flexibility and automated provisioning capabilities of SDN architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple third-party entities are integrated to support SDN deployment, then network functionality and adaptability are improved, but security vulnerability increases due to weak cybersecurity maturity of third parties

Engineering Contradiction:
Improvenetwork functionalityVSAvoidsecurity reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the network access control function by introducing SDP agents in each network slice and an SDP controller that operates independently from the main SDN controller. This segmentation isolates third-party entities within their own secure tunnels, allowing multiple third parties to be integrated for enhanced functionality while preventing security vulnerabilities from propagating across the entire network.

Inventive Principle:
Principle #1Segmentation

3Productivity

If IoT devices and cloud computing are adopted to enhance network capabilities, then network versatility and productivity are improved, but attack surface and security risks worsen

Engineering Contradiction:
Improvenetwork productivityVSAvoidattack surface
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements flexible security encapsulation through SDP tunnels that dynamically wrap around each IoT device and cloud service connection. These encrypted tunnels act as flexible security shells that adapt to different device types and service requirements, allowing extensive IoT and cloud integration for enhanced productivity while containing security risks within isolated encrypted channels.

Inventive Principle:
Principle #30Flexible shells and thin films

4Reliability

If traditional firewall and load balancer are used to control data plane behavior, then network security is improved, but device complexity and difficulty of automation worsen

Engineering Contradiction:
Improvenetwork securityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces traditional mechanical firewall and load balancer devices with a software-based SDP controller that uses northbound APIs for automated policy management. This substitution eliminates complex hardware configurations and manual firewall rule management, providing equivalent or superior security through software-defined perimeter control that can be automatically provisioned and managed through orchestration platforms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20250071090A1Software defined perimeter integration for software defined cellular telecommunications networks
Publication Date: 2025.02.27 EBOS TECH
  • US20250071090A1 patent drawing
  • US20250071090A1 patent drawing
  • US20250071090A1 patent drawing

AI summary

Integrating a software defined perimeter (SDP) for network applications in a 5G/6G telecommunications network includes receiving a registration request from a radio access network (RAN) component of the network into an access and mobility management function (AMF) of the network. The request routes to an SDP controller in the core network component and the SDP controller in turn transmits an authentication request over a virtual private network (VPN) coupling between a main controller and the SDP controller, on behalf of user equipment (UE) and an end user associated with the UE. Finally, responsive to the authentication, the SDP controller generates both an SDP encapsulating a set of network resources of the network supporting microservices accessible by the UE, and a secure tunnel between the UE and a gateway in a data plane of the network that moderates subsequent data flows between the UE and the microservices.