Virtual Private Mobile Network Slice Assignment for Attack Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Virtual Private Mobile Networks (VPMNs) face security risks due to shared network resources, where a compromise in one user group can affect all members, as they share common virtualized slices, leading to increased vulnerability during denial-of-service attacks.
Innovation Solution
Implementing a method to divide VPMN groups into subgroups, each with its own set of virtualized slices, managed by a VPMN manager that assigns UEs to specific slices based on subgroup membership, thereby isolating the impact of attacks to individual subgroups rather than the entire group.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network resources are virtualized to support multiple user groups, then resource utilization and service capability are improved, but security vulnerability increases because a compromise in one user group can affect all members sharing common virtualized slices
Solution Approach 1:
The patent divides VPMN groups into multiple subgroups, where each subgroup is assigned to a dedicated virtualized slice. This segmentation isolates security risks so that a compromise in one subgroup does not affect other subgroups, while still allowing multiple user groups to share network resources through virtualization.
2Loss of energy
If all users in a VPMN group share common virtualized slices, then resource efficiency is improved, but the impact of attacks spreads across the entire group
Solution Approach 1:
The patent segments the VPMN group into multiple subgroups, each with its own virtualized slice assignment. This allows resource sharing within efficiency while limiting attack propagation to only the affected subgroup, preventing system-wide compromise.
3Device complexity
If network elements are initialized with a fixed number of virtualized slices, then system simplicity is maintained, but flexibility to handle different security requirements of different user groups is reduced
Solution Approach 1:
The patent introduces dynamic subgroup management where the network element can adaptively assign users to different subgroups and virtualized slices based on security requirements. This maintains operational simplicity while providing flexible security customization for different user groups.
Data Source
AI summary
Methods and apparatus are disclosed to prevent consecutive attacks on a virtual private mobile network. An example method includes for each of a plurality of network elements, generating virtualized slices based on a virtualized slice count value for subgroups associated with the virtual private mobile network, and assigning non-consecutive ones of the virtualized slices to the subgroups associated with the virtual private mobile network based on demand for the virtualized slices by the respective ones of the subgroups. The example method also includes, in response to a request from a mobile device to access the virtual private mobile network for a first time, assigning the mobile device to one of the virtual slices of the plurality of network elements based on (i) the subgroup associated with the mobile device, and (ii) availability of the virtual slices.


