Smart Cascading Security for 6G Microservices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current deep packet inspection (DPI) technologies are inadequate for effectively implementing smart cascading security functions in 6G and next-generation networks, as they lack the necessary intelligence and adaptability to manage complex network scenarios efficiently.

Innovation Solution

The implementation of smart cascading security functions involves the use of software-defined networking (SDN) and network function virtualization (NFV) to create a dynamic and intelligent network architecture. This architecture allows for real-time traffic management, packet profiling, and microservice-based solutions that can autonomously adapt to changing network conditions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If deep packet inspection (DPI) is used for network security monitoring, then security detection capability is improved, but network processing efficiency deteriorates and device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork processing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the network security function into distributed microservices that can be independently deployed and executed across multiple virtualized network functions. This segmentation allows security inspection to be performed in a distributed manner rather than centralized DPI, improving processing efficiency while maintaining security capabilities through parallel operation of multiple security service instances.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism that decouples the security inspection function from the main network data path. This intermediary approach allows security monitoring to occur without creating bottlenecks in the primary network flow, thereby maintaining both security reliability and network processing efficiency through asynchronous or parallel operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If traditional DPI technologies are used, then basic packet filtering is achieved, but adaptability to complex network scenarios deteriorates

Engineering Contradiction:
Improvenetwork scenario adaptabilityVSAvoidsecurity function effectiveness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements dynamic security services through virtualized network functions that can be instantiated, configured, and deployed dynamically based on network conditions and security requirements. This dynamic approach allows the security system to adapt to complex and changing network scenarios, unlike static traditional DPI systems, while maintaining effective security through on-demand deployment of appropriate security services.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent creates a universal security service framework where a single platform can host multiple different security microservices (e.g., intrusion detection, malware filtering, content inspection). This multi-functional approach provides adaptability to various network scenarios while maintaining reliable security through the ability to deploy the appropriate service for each specific scenario.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If microservice-based virtualized network functions are implemented, then system flexibility and adaptability are improved, but device complexity and deployment difficulty increase

Engineering Contradiction:
Improvesystem flexibilityVSAvoiddeployment complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements self-service capabilities through automated service discovery, registration, and orchestration mechanisms. The microservice-based security functions can automatically register themselves with the orchestration system, discover required resources, and deploy without manual intervention. This self-service approach reduces deployment complexity despite the increased system flexibility provided by microservices.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates feedback mechanisms where the orchestration system continuously monitors the state of virtualized network functions and automatically adjusts resource allocation, service deployment, and configuration based on system performance and security requirements. This closed-loop feedback control simplifies deployment management by automating complex decisions about service placement and resource management.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12219449B2Smart cascading security functions for 6G or other next generation network
Publication Date: 2025.02.04 AT&T INTELLECTUAL PROPERTY I L P
  • US12219449B2 patent drawing
  • US12219449B2 patent drawing
  • US12219449B2 patent drawing

AI summary

In a 6G network, microservices can be utilized in the absence of a core network. For example, after a mobile device has authenticated, through its carrier network, with a transport service layer, microservices can be allocated to the mobile device without having to be transmitted via the core network. Thus, removing the core network from the process can generate a direct line of microservices from the transport layer to the end-user. Furthermore, additional microservices and/or resources can be access through a microservices library. Consequently, packets can be securely transmitted be a wireless network facilitating sending packet profile data from one to many node devices in anticipation of the packet traversing the various node devices.