Virtual Private Mobile Network Slice Assignment for Attack Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Virtual Private Mobile Networks (VPMNs) face security risks due to shared network resources, where a compromise in one user group can affect all members, as they share common virtualized slices, leading to increased vulnerability during denial-of-service attacks.

Innovation Solution

Implementing a method to divide VPMN groups into subgroups, each with its own set of virtualized slices, managed by a VPMN manager that assigns UEs to specific slices based on subgroup membership, thereby isolating the impact of attacks to individual subgroups rather than the entire group.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network resources are virtualized to support multiple user groups, then resource utilization and service capability are improved, but security vulnerability increases because a compromise in one user group can affect all members sharing common virtualized slices

Engineering Contradiction:
Improveservice capabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent divides VPMN groups into multiple subgroups, where each subgroup is assigned to a dedicated virtualized slice. This segmentation isolates security risks so that a compromise in one subgroup does not affect other subgroups, while still allowing multiple user groups to share network resources through virtualization.

Inventive Principle:
Principle #1Segmentation

2Loss of energy

If all users in a VPMN group share common virtualized slices, then resource efficiency is improved, but the impact of attacks spreads across the entire group

Engineering Contradiction:
Improveresource efficiencyVSAvoidattack impact
Core Design Contradiction:
Loss of energyVSObject-affected harmful factors

Solution Approach 1:

The patent segments the VPMN group into multiple subgroups, each with its own virtualized slice assignment. This allows resource sharing within efficiency while limiting attack propagation to only the affected subgroup, preventing system-wide compromise.

Inventive Principle:
Principle #1Segmentation

3Device complexity

If network elements are initialized with a fixed number of virtualized slices, then system simplicity is maintained, but flexibility to handle different security requirements of different user groups is reduced

Engineering Contradiction:
Improvesystem simplicityVSAvoidsecurity customization
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent introduces dynamic subgroup management where the network element can adaptively assign users to different subgroups and virtualized slices based on security requirements. This maintains operational simplicity while providing flexible security customization for different user groups.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9537829B2Methods and apparatus to improve security of a virtual private mobile network
Publication Date: 2017.01.03 AT&T INTELLECTUAL PROPERTY I L P
  • US9537829B2 patent drawing
  • US9537829B2 patent drawing
  • US9537829B2 patent drawing

AI summary

Methods and apparatus are disclosed to prevent consecutive attacks on a virtual private mobile network. An example method includes for each of a plurality of network elements, generating virtualized slices based on a virtualized slice count value for subgroups associated with the virtual private mobile network, and assigning non-consecutive ones of the virtualized slices to the subgroups associated with the virtual private mobile network based on demand for the virtualized slices by the respective ones of the subgroups. The example method also includes, in response to a request from a mobile device to access the virtual private mobile network for a first time, assigning the mobile device to one of the virtual slices of the plurality of network elements based on (i) the subgroup associated with the mobile device, and (ii) availability of the virtual slices.