Quantum ready intelligent security gateway
By introducing a quantum-ready smart security gateway, combined with quantum key distribution and post-quantum cryptography, the threat detection and protection problems of security gateways in mobile networks are solved, achieving high-performance security monitoring and control, and improving the security of mobile networks and the application of contextual information.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- PALO ALTO NETWORKS INC
- Filing Date
- 2024-08-29
- Publication Date
- 2026-04-24
AI Technical Summary
Existing security gateways are unable to effectively detect and prevent threats in mobile network environments, and cannot provide vulnerability protection, antivirus, anti-spyware, cloud-based security integration, DNS security, and threat response from user devices. Furthermore, they lack quantum-ready algorithms and contextual information such as subscriber-ID, device-ID, and network slice-ID.
Employing a quantum-ready smart security gateway that combines quantum key distribution (QKD) and post-quantum cryptography (PQC), it provides vulnerability protection, anti-virus, anti-spyware, cloud security integration, and DNS security. It also supports monitoring and controlling network traffic through intelligent offloading strategies based on contextual information such as subscriber-ID, device-ID, and network slice-ID.
It enhances the security of mobile networks, provides a high-performance security gateway solution, enables comprehensive monitoring and threat protection of the mobile network environment, supports context-based security policy applications, and improves the security and visibility of network traffic.
Smart Images

Figure CN121925818A_ABST
Abstract
Description
Background Technology
[0001] Firewalls generally protect networks from unauthorized access while allowing authorized communication to pass through. A firewall is typically a device or set of devices that provides firewall functionality for network access, or software running on a device such as a computer. For example, a firewall can be integrated into the operating system of a device (e.g., a computer, smartphone, or other type of network-enabled device). Firewalls can also be integrated into, or run as, software on, computer servers, gateways, network / routing devices (e.g., network routers), or data devices (e.g., security devices or other types of dedicated devices).
[0002] Firewalls typically deny or allow network traffic based on rule sets. These rule sets are often called policies. For example, a firewall can filter inbound traffic by applying rule sets or policies. A firewall can also filter outbound traffic by applying rule sets or policies. Firewalls can also perform basic routing functions. Attached Figure Description
[0003] Various embodiments of the invention are disclosed in the following detailed description and the accompanying drawings.
[0004] Figure 1A This is a block diagram of a first example service deployment architecture for 5G and 4G mobile networks with a quantum-ready smart security gateway, according to some embodiments.
[0005] Figure 1B This is a block diagram of a second example service deployment architecture for 5G and 4G mobile networks with a quantum-ready smart security gateway, according to some embodiments.
[0006] Figure 1C This is a block diagram of a third example service deployment architecture for 5G and 4G mobile networks with a quantum-ready smart security gateway, according to some embodiments.
[0007] Figure 1D This is a block diagram of a fourth example service deployment architecture for a 5G mobile network with a quantum-ready smart security gateway, according to some embodiments.
[0008] Figure 1E This is a block diagram of a fifth example service deployment architecture for a 5G mobile network with a quantum-ready smart security gateway, according to some embodiments.
[0009] Figure 1F This is a block diagram of a sixth example service deployment architecture for a 5G mobile network with a quantum-ready smart security gateway, according to some embodiments.
[0010] Figure 1GThis is a block diagram of a seventh example service deployment architecture for a 4G / LTE mobile network with a quantum-ready smart security gateway, according to some embodiments.
[0011] Figure 1H This is a block diagram of an eighth example service deployment architecture for a 4G / LTE mobile network with a quantum-ready smart security gateway, according to some embodiments.
[0012] Figure 1I This is a block diagram of a ninth example service deployment architecture for a 4G / LTE mobile network with a quantum-ready smart security gateway, according to some embodiments.
[0013] Figure 2A This is a block diagram of a first example enterprise deployment architecture for a 5G mobile network with mobile edge computing (MEC) and a quantum-ready smart security gateway, according to some embodiments.
[0014] Figure 2B This is a block diagram of a second example enterprise deployment architecture for a private 5G mobile network with a quantum-ready smart security gateway and only on-premises RAN deployment, according to some embodiments.
[0015] Figure 3 This is a functional diagram of the hardware components of a network device for a quantum-ready smart security gateway, according to some embodiments.
[0016] Figure 4 This is a functional diagram of the logical components of a network device for a quantum-ready smart security gateway, according to some embodiments.
[0017] Figure 5 This is a flowchart of a process for a quantum-ready smart security gateway according to some embodiments.
[0018] Figure 6 This is another flowchart of a process for a quantum-ready smart security gateway according to some embodiments. Detailed Implementation
[0019] This invention can be implemented in a variety of ways, including as a process; an apparatus; a system; a composition of matter; a computer program product embodied on a computer-readable storage medium; and / or a processor, such as a processor configured to execute instructions stored on and / or provided by memory coupled to the processor. In this specification, these embodiments or any other form of the invention may be referred to as technology. Generally, within the scope of this invention, the order of the disclosed process steps can be varied. Unless otherwise stated, components such as processors or memory described as being configured to perform tasks can be implemented as general-purpose components temporarily configured to perform tasks at a given time or as specific components manufactured to perform tasks. As used herein, the term "processor" refers to one or more means, circuits, and / or processing cores configured to process data such as computer program instructions.
[0020] The following provides a detailed description of one or more embodiments of the present invention, along with accompanying drawings illustrating the principles of the invention. The invention is described in conjunction with such embodiments, but is not limited to any particular embodiment. The scope of the invention is defined only by the claims, and the invention includes many alternatives, modifications, and equivalents. Numerous specific details are set forth in the following description to provide a thorough understanding of the invention. These details are provided for illustrative purposes, and the invention may be practiced according to the claims without requiring some or all of these specific details. For clarity, technical materials known in the art related to the invention have not been described in detail so as not to unnecessarily obscure the invention.
[0021] Firewalls generally protect networks from unauthorized access while allowing authorized communication to pass through. A firewall is typically a device, a set of devices, or software running on a device that provides firewall functionality for network access. For example, a firewall can be integrated into the operating system of a device (e.g., a computer, smartphone, or other type of device with network communication capabilities). Firewalls can also be integrated into various types of devices or security devices or executed as software applications on various types of devices or security devices, such as computer servers, gateways, network / routing devices (e.g., network routers), or data devices (e.g., security devices or other types of dedicated devices).
[0022] Firewalls typically deny or allow network traffic based on rule sets. These rule sets are often referred to as policies (e.g., network policies or network security policies). For example, a firewall can filter inbound traffic by applying rule sets or policies to prevent unwanted external traffic from reaching the protected device. Firewalls can also filter outbound traffic by applying rule sets or policies (e.g., specifying allow, block, monitor, notify, or log and / or other actions that can be triggered based on various criteria such as those described herein). Firewalls can also apply antivirus protection, malware detection / prevention, or intrusion protection by applying rule sets or policies.
[0023] Security devices (e.g., security appliances, security gateways, security services, and / or other security devices) may include various security functions (e.g., firewalls, anti-malware, intrusion prevention / detection, proxies, and / or other security functions), networking functions (e.g., routing, quality of service (QoS), workload balancing of network-related resources, and / or other networking functions), and / or other functions. For example, routing functions may be based on source information (e.g., source IP address and port), destination information (e.g., destination IP address and port), and protocol information.
[0024] Basic packet-filtering firewalls filter network traffic by inspecting individual packets transmitted over the network (e.g., packet-filtering firewalls or first-generation firewalls, which are stateless packet-filtering firewalls). Stateless packet-filtering firewalls typically inspect the individual packets themselves and apply rules based on the inspected packets (e.g., using a combination of packet source and destination address information, protocol information, and port numbers).
[0025] Application firewalls can also perform application-layer filtering (e.g., application-layer filtering firewalls or second-generation firewalls that operate at the application layer of the TCP / IP stack). Application-layer filtering firewalls or application firewalls can typically identify certain applications and protocols (e.g., web browsing using Hypertext Transfer Protocol (HTTP), Domain Name System (DNS) requests, file transfer using File Transfer Protocol (FTP), and various other types of applications and protocols such as Telnet, DHCP, TCP, UDP, and TFTP (GSS)). For example, application firewalls can block unauthorized protocols attempting to communicate over standard ports (e.g., application firewalls can often be used to identify unauthorized / policy-exceeding protocols attempting to sneak through non-standard ports using that protocol).
[0026] Stateful firewalls can also perform state-based packet inspection, where each packet is examined within the context of a series of packets associated with a packet flow / packet stream transmitted over the network (e.g., stateful firewalls or third-generation firewalls). This firewall technique is generally referred to as stateful packet inspection because it maintains a record of all connections passing through the firewall and is able to determine whether a packet is the start of a new connection, part of an existing connection, or an invalid packet. For example, the state of a connection itself can be one of the criteria for triggering rules within a policy.
[0027] Advanced or next-generation firewalls can perform stateless and stateful packet filtering, as well as application-layer filtering, as discussed above. Next-generation firewalls can also perform additional firewall technologies. For example, some newer firewalls—sometimes referred to as advanced or next-generation firewalls—can also identify users and content. In particular, some next-generation firewalls are enabling them to automatically identify thousands of applications. Examples of such next-generation firewalls are commercially available from Palo Alto Networks (e.g., Palo Alto Networks' PA series next-generation firewalls, Palo Alto Networks' VM series virtualization next-generation firewalls, and CN series container next-generation firewalls).
[0028] For example, Palo Alto's next-generation firewall enables enterprises and service providers to use a variety of identification technologies to identify and control applications, users, and content, not just ports, IP addresses, and packets. These identification technologies include, for example, APP-IDs for accurate application identification. TM (For example, APP-ID), User-ID used for user identification TM (For example, user-ID) (e.g., by user or user group), and content-ID used for real-time content scanning. TM (For example, content-ID) (e.g., controlling web browsing and restricting data and file transfers). These identification technologies allow businesses to securely implement application usage using business-relevant concepts rather than following traditional methods provided by conventional port-blocking firewalls. Furthermore, dedicated hardware for next-generation firewalls (e.g., implemented as dedicated devices) typically offers a higher level of application inspection performance than software running on general-purpose hardware (e.g., security appliances such as those from Palo Alto Networks, which use dedicated function-specific processing tightly integrated with a single-pass software engine to maximize network throughput while minimizing latency in Palo Alto Networks' PA series of next-generation firewalls).
[0029] Overview of technologies for applying quantum-ready smart security gateways For devices in mobile networks (e.g., 4G / LTE, 5G, and later mobile networks), there are technical and security challenges for service provider networks.
[0030] Specifically, the 3rd Generation Partnership Project (3GPP) recommends that the Security Gateway (SEG) provide Internet Protocol Security (IPsec) tunnels to secure backhaul traffic between radio access and the core network in mobile network environments such as 4G / LTE, 5G and beyond.
[0031] However, existing SEGs typically fail to detect and prevent threats and malicious communications on mobile networks. Furthermore, before allowing network traffic (e.g., via the N3 and N4 interfaces in 5G and the S1-U and / or S11 interfaces in 4G / LTE) to traverse the mobile network to reach the internet boundary, existing SEGs generally lack vulnerability protection, antivirus, anti-spyware, cloud-based security integration, DNS security for early detection, and / or response to threats originating from user equipment (UE). Additionally, existing SEGs typically do not provide subscriber-ID / International Mobile Subscriber Identity (IMSI), device-ID / International Mobile Equipment Identity (IMEI), network slice ID / Single Network Slice Selection Auxiliary Information (S-NSSAI), IP-to-mobile subscriber traffic mapping within GTP-U tunnels, etc.
[0032] Furthermore, 3GPP has not yet introduced quantum-ready algorithms for mobile networks, including SEG for mobile network environments. Specifically, current 3GPP specifications include IETF protocols, such as TLS, DTLS, EAP-TLS, and X.509.
[0033] Accordingly, what is needed for devices communicating over such service provider network environments (e.g., mobile networks, which include various 4G / LTE, 5G and beyond mobile networks) are new and improved security technologies.
[0034] Specifically, what is needed are new and improved solutions for monitoring such network traffic and applying quantum-ready smart security gateways to mobile network environments, such as devices (e.g., UEs) that communicate over service provider networks (e.g., including subscriber-ID / International Mobile Subscriber Identity (IMSI), device-ID / International Mobile Equipment Identity (IMEI), network slice ID / Single Network Slice Selection Assistance Information (S-NSSAI), IP-to-mobile subscriber traffic mapping within GTP-U tunnels, and / or other context-based information to facilitate enhanced security in such mobile network environments).
[0035] Therefore, the disclosed technology facilitates system / process / computer program products for quantum-ready smart security gateways, which will be further described below.
[0036] In an example implementation, a quantum-ready smart security gateway is disclosed that facilitates one or more of the following: (1) Traditional SEGs that support IPsec security protocols and packet filtering as specified by 3GPP; (2) Vulnerability protection / intrusion prevention system (IPS), antivirus, anti-spyware, cloud security integration / support (e.g., for cloud-based security analytics), DNS security, and / or denial-of-service (DoS) protection; (3) Subscriber-ID / IMSI, Device-ID / IMEI, Network Slice ID / Single Network Slice Selection Auxiliary Information (S-NSSAI), and / or other mobile context level visibility and enforcement capabilities for mobile subscriber traffic within the GTP-U tunnel; (4) Support for post-quantum security technologies, including quantum key distribution (QKD) and post-quantum cryptography (PQC) solutions (see, for example, the National Institute of Standards and Technology (NIST) proposals for: FIPS 203, a standard for lattice-based key encapsulation mechanisms (available at https: / / CSRC.NIST.gov / pubs / FIPS / 203 / ipd); FIPS 204, a standard for lattice-based digital signatures (available at https: / / CSRC.NIST.gov / pubs / FIPS / 204 / ipd); and FIPS 205, a standard for stateless hash-based digital signatures (available at https: / / CSRC.NIST.gov / pubs / FIPS / 205 / ipd)); and (5) Supports a variety of intelligent traffic offloading functions (such as those disclosed in U.S. Patent No. 11665139, which is hereby incorporated herein by reference in its entirety) to significantly improve the performance of the security gateway.
[0037] In some embodiments, the system / process / computer program product for applying a quantum-ready smart security gateway includes: a quantum-ready smart security gateway (e.g., supporting quantum key distribution (QKD) and / or post-quantum cryptography (PQC)) for providing secure tunneling to a mobile network, for example by implementing NIST proposals to: FIPS 203, a modular lattice-based key encapsulation mechanism standard (available at https: / / CSRC.NIST.gov / pubs / FIPS / 203 / ipd); FIPS 204, a modular lattice-based digital signature standard (available at https: / / CSRC.NIST.gov / pubs / FIPS / 204 / ipd); and FIPS 205, the Stateless Hash-Based Digital Signature Standard (available at https: / / CSRC.NIST.gov / pubs / FIPS / 205 / ipd), monitors network traffic on mobile networks to identify new sessions; determines metadata associated with new sessions by extracting metadata from network traffic via one or more interfaces; and applies security policies to new sessions at security gateways based on the metadata to apply context-based security in mobile networks.
[0038] For example, a security gateway may include a quantum-ready smart security gateway that supports intelligent offloading of monitored network traffic based on offloading policies.
[0039] As another example, a security gateway can be configured with multiple security policies to apply subscriber ID-based security, device-ID-based security, and / or network slice-ID-based security in a mobile network.
[0040] As yet another example, a security gateway can be configured with multiple security policies to apply vulnerability protection, intrusion prevention, antivirus, anti-spyware, DNS security, denial-of-service (DoS) protection, and / or cloud-based security.
[0041] In some embodiments, the system / process / computer program product for applying the quantum-ready smart security gateway also includes performing level threat identification and prevention in mobile networks.
[0042] In some embodiments, the system / process / computer program product for applying a quantum-ready smart security gateway also includes performing application identification and control in a mobile network.
[0043] In some embodiments, the system / process / computer program product for applying a quantum-ready smart security gateway also includes performing URL filtering in a mobile network.
[0044] In some embodiments, the system / process / computer program product for applying a quantum-ready smart security gateway also includes blocking new sessions from accessing resources based on security policies.
[0045] In some embodiments, the system / process / computer program product for applying a quantum-ready smart security gateway also includes allowing new sessions to access resources based on security policies.
[0046] In the example implementation, the disclosed quantum-ready smart security gateway facilitates the high-performance capabilities of a quantum-ready security gateway, provides a variety of intelligent traffic offloading functions, and offers mobile identity and context-level visibility and implementation in mobile network environments to enhance security.
[0047] Furthermore, the disclosed quantum-ready smart security gateway supports post-quantum security technologies, including quantum key distribution (QKD) and / or post-quantum cryptography (PQC).
[0048] In addition, the disclosed quantum-ready smart security gateway can provide security services, including, for example, vulnerability protection / IPS, antivirus, anti-spyware, cloud security integration, DNS security, and DoS protection.
[0049] In addition, the disclosed quantum-ready smart security gateway solution provides enterprise customers with a security gateway (SEG) solution that combines identity-based security with VPN technology to facilitate zero trust in private mobile networks.
[0050] Therefore, the disclosed technology for quantum-ready smart security gateways helps to enhance security in mobile networks.
[0051] Therefore, according to some embodiments, new and improved security solutions are disclosed that facilitate the application of security (e.g., network-based security) on various interfaces (e.g., N2, N3, S1-U, S11, etc.) and protocols (e.g., GTP-U, IPsec, NGAP, S1AP, etc.) in mobile network environments using quantum-ready smart security gateways disclosed in mobile networks (e.g., 4G / 5G / later versions of mobile networks). These quantum-ready smart security gateways can be implemented using firewalls (FW) / next-generation firewalls (NGFW), network sensors acting on behalf of firewalls, or other (virtual) devices / components that can implement security policies using the disclosed technologies (including, for example, Palo Alto Networks' PA series next-generation firewalls, Palo Alto Networks' VM series virtualized next-generation firewalls, and CN series container next-generation firewalls, and / or other commercially available virtual or container-based firewalls that can be similarly implemented and configured to perform the disclosed technologies).
[0052] These and other embodiments and examples for applying quantum-ready smart security gateways in mobile networks will be further described below.
[0053] Example system architecture for applying a quantum-ready smart security gateway. Therefore, in some embodiments, the disclosed technology includes providing a quantum-ready smart security gateway (e.g., one or more security functions / one or more platforms may be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor acting on behalf of the firewall, or another (virtual) device / component that may implement security policies using the disclosed technology (e.g., PANOS implemented on a commercially available virtual / physical NGFW solution from Palo Alto Networks, Inc. or another security platform / NFGW, including, for example, Palo Alto Networks' PA series next-generation firewalls, Palo Alto Networks' VM series virtualized next-generation firewalls, and CN series container next-generation firewalls, and / or other commercially available virtual-based or container-based firewalls that may be similarly implemented and configured to implement the disclosed technology)). This quantum-ready smart security gateway is configured to implement security policies through various interfaces (e.g., RESTful...). API, S1-U, N3 and / or other interfaces in core 4G / LTE, 5G and beyond mobile networks) provide DPI capabilities (e.g., including stateful inspection) for GTP-U sessions (e.g., GTP-U traffic) to apply security to traffic in the mobile network based on policies (e.g., Layer 7 security and / or other security policy implementations), as further described below.
[0054] Specifically, as will now be described for various system embodiments, context-based security can be applied using a quantum-ready smart security gateway in mobile networks (including 4G / LTE, 5G, and future mobile networks), as will be described below for various embodiments. In example implementations, context-based security can be applied in mobile networks using a quantum-ready smart security gateway based on one or more of the following: IMSI, IMEI, subscriber / user type RAT, network slice, DNN / APN, location, user IP, and / or other contextual information. The quantum-ready smart security gateway can be deployed on, for example, the S1-U and / or S11 interfaces in 4G / LTE networks and the N3 and / or N4 interfaces in 5G networks.
[0055] Figure 1A This is a block diagram of a first example service deployment architecture for 5G and 4G mobile networks with a quantum-ready smart security gateway, according to some embodiments.
[0056] Specifically, Figure 1A This is a first example of a service deployment architecture for 5G and 4G mobile networks, which includes a quantum-ready smart security gateway 102 (e.g., one or more security functions / one or more platforms can be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor acting on behalf of the firewall, or another (virtual) device / component that can implement security policies using disclosed technologies, including, for example, Palo Alto Networks' PA series next-generation firewalls, Palo Alto Networks' VM series virtualized next-generation firewalls, and CN series container next-generation firewalls, and / or other commercially available virtual or container-based firewalls that can be similarly implemented and configured to perform the disclosed technologies). The quantum-ready smart security gateway 102 is used to implement quantum-ready security protocol algorithms and apply context-based security in the mobile network through various interfaces in the mobile network (e.g., 4G / LTE or later mobile networks) (e.g., S1-U, S11 and / or other interfaces in the 4G / LTE core network, and N2 and / or other interfaces in the 5G core network), as further described below.
[0057] As cited in this article, IMSI is a concept referred to by the ITU-T as "International Mobile Subscriber Identity". IMSI is a 14 or 15-digit number.
[0058] As cited in this article, the SUPI is a globally unique 5G "subscription permanent identifier" assigned to each subscriber in a 5G system. According to 3GPP TS 23.003 Release 16.9.0, the SUPI type can indicate IMSI, Network Access Identifier (NAI), Global Line Identifier (GLI), or Global Cable Identifier (GCI).
[0059] As cited in this article, the International Mobile Equipment Identity (IMEI) can be found at https: / / portal.3gpp.org / desktopmodules / Specifications / SpecificationDetails.aspx Defined in 3GPP TS 23.003 obtained from specificationId=729.
[0060] like Figure 1AAs shown, the 5G mobile network environment may also include 5G radio access network (RAN) access as shown in 106A, 4G radio access network (RAN) access as shown in 106B, and / or other networks such as Wi-Fi access and fixed access (not shown) to facilitate subscriber data communications (e.g., using user equipment (UE), such as smartphones, laptops, computers (which may be in a fixed location), and Internet of Things (IoT) devices and / or other cellular-enabled computing devices / devices as shown in 104, and / or other network-enabled devices, including access to various applications, network services, content hosts, etc. and / or other networks via packet data network (PDN) (e.g., the Internet) 120). Each of the above-described 4G / LTE and 5G network access mechanisms securely communicates with the 4G / LTE and 5G core networks 110. Specifically, 5G RAN 106A and 4G RAN 106B are in IPSec communication (e.g., including management plane and communication plane communication via the N2 interface and S1 interface, respectively), as shown.
[0061] Referring to the 5G core and 4G core (EPC) mobile network 110, the UPF and PGW-U 112 communicate with the PDN (Internet) 120. The security gateway 102 communicates with the MME 111 via the S1-Mobility Management Entity (MME) interface (e.g., control plane communication). The security gateway 102 also communicates with the Operation, Management and Maintenance (OAM) 115 (e.g., management plane communication via the N2 interface). As also shown, the 5G core and 4G core (EPC) mobile network 110 includes a Session Management Function (SMF) and a Packet Gateway Control Plane (PGW-C) 113 (e.g., communicating with the security gateway 102 via the N2 interface to access UE IP, IMEI, IMSI and / or other contextual information, which will be further described below), a Dynamic Host Control Protocol (DHCP) server 116, and a Registration Authority (RA) / Certification Authority (CA) 118.
[0062] refer to Figure 1AThe security gateway 102 is used to monitor network traffic communications. As shown, the security gateway 102 is used to monitor / filter network traffic communications in the 5G core and 4G core (EPC) mobile networks 110. The security gateway 102 (e.g., a (virtual) device / app that includes a firewall (FW) in each, a network sensor acting on behalf of the firewall, or another device / component that can implement security policies using the disclosed techniques) is configured to perform the disclosed techniques for applying context-based security in the mobile network through various interfaces (e.g., S1-U, S11, S1, N2, and / or other interfaces in the 5G core and 4G core (EPC) mobile networks 110), as described above and further described below.
[0063] In this example implementation, a security platform deployed in a mobile network based on 4G / LTE and 5G technologies can be used to implement the disclosed technologies for applying quantum-ready smart security gateways, such as... Figure 1A As shown. Specifically, security gateway 102 can be configured to implement one or more quantum-ready security protocol algorithms (e.g., supporting post-quantum security technologies including quantum key distribution (QKD), post-quantum cryptography (PQC) solutions (e.g., see NIST proposals for: FIPS 203, a modular lattice-based key encapsulation mechanism standard (available at https: / / CSRC.NIST.gov / pubs / FIPS / 203 / ipd); FIPS 204, a modular lattice-based digital signature standard (available at https: / / CSRC.NIST.gov / pubs / FIPS / 204 / ipd); and FIPS 205, a stateless hash-based digital signature standard (available at https: / / CSRC.NIST.gov / pubs / FIPS / 205 / ipd), applies context-based security in mobile networks through various interfaces in mobile networks (e.g., 4G / LTE or later mobile networks), such as S1-U, S11 and / or other interfaces in the 4G / LTE core network, and the N2 interface and / or other interfaces in the 5G core network, as further described below.
[0064] In some embodiments, security gateway 102 is further configured to provide DPI capabilities for IP traffic on the N2 interface. In an example implementation, the security platform is configured to provide DPI capabilities (e.g., including identifying APP ID, user ID, content ID, performing URL filtering, etc.) for IP sessions, such as through N2 and / or other interfaces between the UPF and PGW-U112 and PDN 120, to apply security to user plane traffic based on policies (e.g., Layer 7 security and / or other security policy implementations), as further described below.
[0065] In addition, security gateway 102 can also connect to cloud security service 122 (e.g., commercially available cloud-based security services, such as WildFire-based security services). TM (WF) cloud malware analysis environment, a commercially available cloud security service provided by Palo Alto Networks, Inc., includes automated security analysis of malware samples and analysis by security experts (or may utilize similar solutions from another vendor) for network communication, such as via the Internet. For example, cloud security service 122 can be used to provide dynamic preventative signatures against malware, DNS, URL, CNC malware, and / or other malware to a security platform, and to receive malware samples for further security analysis.
[0066] Figure 1B This is a block diagram of a second example service deployment architecture for 5G and 4G mobile networks with a quantum-ready smart security gateway, according to some embodiments.
[0067] Specifically, Figure 1BThis is a second example of a service deployment architecture for 5G and 4G mobile networks, which includes a quantum-ready smart security gateway 102 (e.g., one or more security functions / one or more platforms may be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor acting on behalf of the firewall, or another (virtual) device / component that may implement security policies using disclosed technologies, including, for example, Palo Alto Networks' PA series next-generation firewalls, Palo Alto Networks' VM series virtualized next-generation firewalls, and CN series container next-generation firewalls, and / or other commercially available virtual or container-based firewalls that may be similarly implemented and configured to perform the disclosed technologies). The quantum-ready smart security gateway 102 is used to implement quantum-ready security protocol algorithms and apply context-based security in the mobile network (e.g., 4G / LTE or later mobile networks) through various interfaces (e.g., S1-U, S11 and / or other interfaces in the 4G / LTE core network, and N3 and / or other interfaces in the 5G core network), as further described below.
[0068] like Figure 1B As shown, each of the above 4G / LTE and 5G network access mechanisms securely communicates with the 4G / LTE and 5G core network 110, as referenced above. Figure 1A Similarly, in a second example of a service deployment architecture for a 5G and 4G mobile network with a quantum-ready smart security gateway 102, 5G RAN 106A and 4G RAN 106B are in IPSec communication (e.g., they include user plane and management plane communication on the N3 interface and control plane communication on the N2 and S1-MME interfaces, respectively). Also as shown, the quantum-ready smart security gateway 102 communicates with the SMF and PGW-C 113 via the N2 interface for control plane communication, with the MME 111 via the S1-MME interface for user plane communication, with the UPF and PGW-U 112 via the N3 interface for user plane communication, and with the OAM 115 via the N3 interface for management plane communication (as shown).
[0069] Figure 1C This is a block diagram of a third example service deployment architecture for 5G and 4G mobile networks with a quantum-ready smart security gateway, according to some embodiments.
[0070] Specifically, Figure 1CA third example of a service deployment architecture for 5G and 4G mobile networks includes a quantum-ready smart security gateway 102 (e.g., one or more security functions / one or more platforms may be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor acting on behalf of the firewall, or another (virtual) device / component that may implement security policies using disclosed technologies, including, for example, Palo Alto Networks' PA series next-generation firewalls, Palo Alto Networks' VM series virtualized next-generation firewalls, and CN series container next-generation firewalls, and / or other commercially available virtual-based or container-based firewalls that may be similarly implemented and configured to perform the disclosed technologies). This quantum-ready smart security gateway 102 is used to implement quantum-ready security protocol algorithms and apply context-based security in the mobile network (e.g., 4G / LTE or later mobile networks) through various interfaces (e.g., S1-U, S11 and / or other interfaces in the 4G / LTE core network, and N3 and / or other interfaces in the 5G core network), as further described below.
[0071] like Figure 1C As shown, each of the above 4G / LTE and 5G network access mechanisms securely communicates with the 4G / LTE and 5G core network 110, as referenced above. Figure 1A Similarly, in a third example of a service deployment architecture for 5G and 4G mobile networks with a quantum-ready smart security gateway 102, 5G RAN 106A and 4G RAN 106B are in IPSec communication (e.g., including user plane and management plane communication on the N3 interface and control plane communication on the N2 and S1-MME interfaces, respectively). Also as shown, the quantum-ready smart security gateway 102 communicates with the SMF and PGW-C113 via the N2 and / or other interfaces in the control plane, with the MME 111 via the S1-MME interface in the user plane, with the UPF and PGW-U112 via the N3 interface in the user plane, and with the OAM 115 via the N3 interface in the management plane (as shown).
[0072] Figure 1D This is a block diagram of a fourth example service deployment architecture for a 5G mobile network with a quantum-ready smart security gateway, according to some embodiments.
[0073] Specifically, Figure 1DA fourth example of a service deployment architecture for a 5G mobile network includes a quantum-ready smart security gateway 102 (e.g., one or more security functions / one or more platforms may be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor acting on behalf of the firewall, or another (virtual) device / component that may implement security policies using disclosed technologies, including, for example, Palo Alto Networks' PA series next-generation firewalls, Palo Alto Networks' VM series virtualized next-generation firewalls, and CN series container next-generation firewalls, and / or other commercially available virtual-based or container-based firewalls that may be similarly implemented and configured to perform the disclosed technologies). This quantum-ready smart security gateway 102 is used to implement quantum-ready security protocol algorithms and apply context-based security in the mobile network through various interfaces in the mobile network (e.g., 5G or later mobile networks) (e.g., N2, N3 and / or other interfaces in the 5G core network), as further described below.
[0074] like Figure 1D As shown, each of the above 5G network access mechanisms communicates securely with the 5G core network 110, as referenced above. Figure 1A Similarly, in a fourth example of a service deployment architecture for a 5G mobile network with a quantum-ready smart security gateway 102, 5G RAN 106A and 5G RAN 106B are in IPSec communication as shown (e.g., including management plane and control plane communication via the N2 interface). Also as shown, the quantum-ready smart security gateway 102 communicates with the UPF 112 in the user plane via the N3 interface, with the SMF 113 in the control plane via the N2 interface, and with the OAM 115 in the management plane via the N2 interface (as shown).
[0075] Figure 1E This is a block diagram of a fifth example service deployment architecture for a 5G mobile network with a quantum-ready smart security gateway, according to some embodiments.
[0076] Specifically, Figure 1EA fifth example of a service deployment architecture for a 5G mobile network includes a quantum-ready smart security gateway 102 (e.g., one or more security functions / one or more platforms may be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor acting on behalf of the firewall, or another (virtual) device / component that may implement security policies using disclosed technologies, including, for example, Palo Alto Networks' PA series next-generation firewalls, Palo Alto Networks' VM series virtualized next-generation firewalls, and CN series container next-generation firewalls, and / or other commercially available virtual-based or container-based firewalls that may be similarly implemented and configured to perform the disclosed technologies). This quantum-ready smart security gateway 102 is used to implement quantum-ready security protocol algorithms and apply context-based security in the mobile network through various interfaces in the mobile network (e.g., 5G or later mobile networks) (e.g., N2, N3 and / or other interfaces in the 5G core network), as further described below.
[0077] like Figure 1E As shown, each of the above 5G network access mechanisms communicates securely with the 5G core network 110, as referenced above. Figure 1A Similarly, in a fifth example of a service deployment architecture for a 5G mobile network with a quantum-ready smart security gateway 102, 5G RAN 106A and 5G RAN 106B are in IPSec communication (e.g., including user plane communication via the N3 interface and management plane and control plane communication via the N2 interface), as shown. Also as shown, the quantum-ready smart security gateway 102 communicates with UPF 112 via the N3 interface for user plane communication, with SMF 113 via the N2 interface for control plane communication, and with OAM 115 via the N2 interface for management plane communication (as shown).
[0078] Figure 1F This is a block diagram of a sixth example service deployment architecture for a 5G mobile network with a quantum-ready smart security gateway, according to some embodiments.
[0079] Specifically, Figure 1FA sixth example of a service deployment architecture for a 5G mobile network includes a quantum-ready smart security gateway 102 (e.g., one or more security functions / one or more platforms may be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor acting on behalf of the firewall, or another (virtual) device / component that may implement security policies using disclosed technologies, including, for example, Palo Alto Networks' PA series next-generation firewalls, Palo Alto Networks' VM series virtualized next-generation firewalls, and CN series container next-generation firewalls, and / or other commercially available virtual-based or container-based firewalls that may be similarly implemented and configured to perform the disclosed technologies). This quantum-ready smart security gateway 102 is used to implement quantum-ready security protocol algorithms and apply context-based security in the mobile network through various interfaces in the mobile network (e.g., 5G or later mobile networks) (e.g., N2, N3 and / or other interfaces in the 5G core network), as further described below.
[0080] like Figure 1F As shown, each of the above 5G network access mechanisms communicates securely with the 5G core network 110, as referenced above. Figure 1A Similarly, in a sixth example of a service deployment architecture for a 5G mobile network with a quantum-ready smart security gateway 102, 5G RAN 106A and 5G RAN 106B are in IPSec communication (e.g., including user plane communication via the N3 interface and management plane and control plane communication via the N2 interface). Also as shown, the quantum-ready smart security gateway 102 communicates with the UPF 112 via the N3 interface in the user plane; and with the SMF 113 via the N2 and N4 interfaces in the control plane, where intelligence can be collected via the N4 interface for mapping UE IP, IMEI, IMSI, location, network slices, and / or other contextual information for application security (as described similarly herein); and for management plane communication with the OAM 115 via the N2 interface (as shown).
[0081] Figure 1G This is a block diagram of a seventh example service deployment architecture for a 4G / LTE mobile network with a quantum-ready smart security gateway, according to some embodiments.
[0082] Specifically, Figure 1GA seventh example of a service deployment architecture for a 4G / LTE mobile network includes a quantum-ready smart security gateway 102 (e.g., one or more security functions / one or more platforms may be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor acting on behalf of the firewall, or another (virtual) device / component that may implement security policies using disclosed technologies, including, for example, Palo Alto Networks' PA series next-generation firewalls, Palo Alto Networks' VM series virtualized next-generation firewalls, and CN series container next-generation firewalls, and / or other commercially available virtual or container-based firewalls that may be similarly implemented and configured to perform the disclosed technologies). This quantum-ready smart security gateway 102 is used to implement quantum-ready security protocol algorithms and apply context-based security in the mobile network through various interfaces in the mobile network (e.g., the S1-MME interface and / or other interfaces in the 4G / LTE core network), as further described below.
[0083] like Figure 1G As shown, each of the above 4G / LTE network access mechanisms securely communicates with the 4G core (EPC) network 110, as referenced above. Figure 1A Similarly, in a seventh example of a service deployment architecture for a 4G / LTE mobile network with a quantum-ready smart security gateway 102, 4G RAN 106A and 4G RAN 106B are in IPSec communication (e.g., including management plane and control plane communication via the S1-MME interface), as shown. Also as shown, the quantum-ready smart security gateway 102 communicates with the MME 111 in the control plane via the S1-MME interface and with the OAM 115 in the management plane via the S1-MME interface (as shown).
[0084] Figure 1H This is a block diagram of an eighth example service deployment architecture for a 4G / LTE mobile network with a quantum-ready smart security gateway, according to some embodiments.
[0085] Specifically, Figure 1HAn eighth example of a service deployment architecture for a 4G / LTE mobile network includes a quantum-ready smart security gateway 102 (e.g., one or more security functions / one or more platforms may be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor acting on behalf of the firewall, or another (virtual) device / component that may implement security policies using disclosed technologies, including, for example, Palo Alto Networks' PA series next-generation firewalls, Palo Alto Networks' VM series virtualized next-generation firewalls, and CN series container next-generation firewalls, and / or other commercially available virtual-based or container-based firewalls that may be similarly implemented and configured to perform the disclosed technologies). This quantum-ready smart security gateway 102 is used to implement quantum-ready security protocol algorithms and apply context-based security in the mobile network through various interfaces in the mobile network (e.g., the S1-MME interface and / or other interfaces in the 4G / LTE core network), as further described below.
[0086] like Figure 1H As shown, each of the above 4G / LTE network access mechanisms securely communicates with the 4G core (EPC) network 110, as referenced above. Figure 1A Similarly, in the eighth example of the service deployment architecture of a 4G / LTE mobile network with a quantum-ready smart security gateway 102, 4G RAN 106A and 4G RAN 106B are in IPSec communication (e.g., including user plane communication via the S1-U interface and management plane and control plane communication via the S1-MME interface), as shown. Also as shown, the quantum-ready smart security gateway 102 communicates with the SGW 117 via the S1-U interface for user plane communication, with the MME 111 via the S1-MME interface for control plane communication, and with the OAM 115 via the S1-MME interface for management plane communication (as shown).
[0087] Figure 1I This is a block diagram of a ninth example service deployment architecture for a 4G / LTE mobile network with a quantum-ready smart security gateway, according to some embodiments.
[0088] Specifically, Figure 1IA ninth example of a service deployment architecture for a 4G / LTE mobile network includes a quantum-ready smart security gateway 102 (e.g., one or more security functions / one or more platforms may be implemented using a firewall (FW) / next-generation firewall (NGFW), a network sensor acting on behalf of the firewall, or another (virtual) device / component that may implement security policies using disclosed technologies, including, for example, Palo Alto Networks' PA series next-generation firewalls, Palo Alto Networks' VM series virtualized next-generation firewalls, and CN series container next-generation firewalls, and / or other commercially available virtual or container-based firewalls that may be similarly implemented and configured to perform the disclosed technologies). This quantum-ready smart security gateway 102 is used to implement quantum-ready security protocol algorithms and apply context-based security in the mobile network through various interfaces in the mobile network (e.g., the S1-MME interface and / or other interfaces in the 4G / LTE core network), as further described below.
[0089] like Figure 1I As shown, each of the above 4G / LTE network access mechanisms securely communicates with the 4G core (EPC) network 110, as referenced above. Figure 1A Similarly, in a ninth example of a service deployment architecture for a 4G / LTE mobile network with a quantum-ready smart security gateway 102, 4G RAN 106A and 4G RAN 106B are in IPSec communication (e.g., including user plane communication via the S1-U interface and management plane and control plane communication via the S1-MME interface), as shown. Also as shown, the quantum-ready smart security gateway 102 communicates with the SGW 117 in the user plane via the S1-U interface and in the control plane via the S11 interface, where intelligence can be collected via the S11 interface for mapping UE IP, IMEI, IMSI, and / or other contextual information for application security (as similarly described herein); and communicates in the control plane with the MME 111 via the S1-MME and S11 interfaces, and in the management plane with the OAM 115 via the S1-MME interface (as shown).
[0090] Figure 2A This is a block diagram of a first example enterprise deployment architecture for a 5G mobile network with mobile edge computing (MEC) and a quantum-ready smart security gateway, according to some embodiments.
[0091] Specifically, Figure 2AFor a first example enterprise deployment architecture of a 5G mobile network with MEC, which includes quantum-ready smart security gateways 102A and 102B (e.g., security functions / platforms that can be implemented using firewalls (FW) / next-generation firewalls (NGFW), network sensors acting on behalf of firewalls, or another (virtual) device / component that can implement security policies using disclosed technologies, including, for example, Palo Alto Networks' PA series next-generation firewalls, Palo Alto Networks' VM series virtualized next-generation firewalls, and CN series container next-generation firewalls, and / or other commercially available virtual-based or container-based firewalls that can be similarly implemented and configured to perform the disclosed technologies), the quantum-ready smart security gateways 102A and 102B are used to implement quantum-ready security protocol algorithms and apply context-based security in the mobile network through various interfaces in the mobile network (e.g., 5G or later mobile networks) (e.g., N2 and N3 interfaces and / or other interfaces in the 5G core network), as further described below.
[0092] like Figure 2A As shown, the 5G mobile network environment may also include 5G radio access network (RAN) access as shown in 106A, and / or other networks such as Wi-Fi access and fixed access (not shown) to facilitate subscriber data communications (e.g., using user equipment (UE), such as smartphones, laptops, computers (which may be in a fixed location), and Internet of Things (IoT) devices and / or other cellular-enabled computing devices / devices as shown in 104, and / or other network-enabled devices, including access to various applications, network services, content hosts, etc. and / or other networks via packet data network (PDN) (e.g., the Internet) 120). Each of the above-described 5G network access mechanisms securely communicates with the 5G core network 110A and 5G MEC 110B in the central core site 109. Specifically, as shown, 5G RAN 106A communicates with security gateway 102A via IPSec (e.g., including user plane communication via N3), and with security gateway 102B via IPSec (e.g., including management plane and communication plane communication via the N2 interface).
[0093] Referring to 5G MEC 110B, security gateway 102A communicates with the User Plane Function (UPF) and Packet Gateway User Plane (PGW-U) 112 via the N3 interface (e.g., user plane communication). UPF and PGW-U 112 communicate with PDN (Internet Protocol Network) 120 via the N3, N4 / S1-U, and S11 interfaces, with security gateway 102A situated in the line between UPF, PGW-U 112, and PDN 120. Security gateway 102A (e.g., via the N3 and N4 interfaces, as shown) communicates with UPF and PGW-U 112 to access UE IP, IMEI, IMSI, and / or other contextual information, which will be further described below.
[0094] Referring to a central core site 109 including a 5G core mobile network 110A, a security gateway 102B communicates via an N2 interface for the central core site 109 (e.g., user plane communication). Also shown, the central core site 109 includes an Operation, Administration and Maintenance (OAM) 115 and a Registration Authority (RA) / Certification Authority (CA) 118.
[0095] refer to Figure 2A Security gateways 102A and 102B are used to monitor network traffic communications. As shown, in the 5G MEC 110B and the central core site 109, security gateways 102A and 102B (e.g., each including a (virtual) device / apparatus of a firewall (FW), a network sensor acting on behalf of the firewall, or another device / component that can implement security policies using the disclosed techniques) are used to monitor / filter network traffic communications. Security gateways 102A and 102B are configured to perform the disclosed techniques for applying context-based security, as described above and further described below, through various interfaces in the mobile network (e.g., S1-U, S11, S1, N2, N3, N4 and / or other interfaces in the 5G MEC 110B and the central core site 109).
[0096] In this embodiment, the disclosed technology for applying quantum-ready smart security gateways can be implemented using a security platform deployed in a 5G-based mobile network, such as... Figure 2AAs shown. Specifically, security gateways 102A and 102B can be configured to implement one or more quantum-ready security protocol algorithms (e.g., supporting post-quantum security technologies, including quantum key distribution (QKD), post-quantum cryptography (PQC) solutions (e.g., see NIST proposals for: FIPS 203, a modular lattice-based key encapsulation mechanism standard (available at https: / / CSRC.NIST.gov / pubs / FIPS / 203 / ipd); FIPS 204, a modular lattice-based digital signature standard (available at https: / / CSRC.NIST.gov / pubs / FIPS / 204 / ipd); and FIPS 205, a stateless hash-based digital signature standard (available at https: / / CSRC.NIST.gov / pubs / FIPS / 205 / ipd)), and via various interfaces in mobile networks (e.g., 5G or later mobile networks) (e.g., S1-U, S11, S1, N2, N3, N4 and / or in 5G MEC). Other interfaces in 110B and the central core site 109 apply context-based security in mobile networks, as further described below.
[0097] In some embodiments, the security gateway 102A is further configured to provide DPI capabilities for IP traffic over the N4 interface. In an example implementation, the security platform is configured to provide DPI capabilities (e.g., including identifying APP ID, user ID, content ID, performing URL filtering, etc.) for IP sessions over the N3 and N4 interfaces between the UPF and PGW-U 112 and PDN 120, to apply security to user plane traffic based on policies (e.g., Layer 7 security and / or other security policy implementations), as further described below.
[0098] In addition, security gateway 102A can also connect to cloud security service 122 (e.g., commercially available cloud-based security services, such as WildFire-based security services). TM (WF) cloud malware analysis environment, a commercially available cloud security service provided by Palo Alto Networks, Inc., includes automated security analysis of malware samples and analysis by security experts (or may utilize similar solutions from another vendor) for network communication, such as via the Internet. For example, cloud security service 122 can be used to provide dynamic preventative signatures against malware, DNS, URL, CNC malware, and / or other malware to a security platform, and to receive malware samples for further security analysis.
[0099] Figure 2BThis is a block diagram of a second example enterprise deployment architecture for a private 5G mobile network with only RAN local deployment and a quantum-ready smart security gateway, according to some embodiments.
[0100] Specifically, Figure 2B A second example of a service deployment architecture for a private 5G mobile network with only RAN local deployment includes a quantum-ready smart security gateway 102 (e.g., implemented using a firewall (FW) / next-generation firewall (NGFW), network sensors acting on behalf of the firewall, or another (virtual) device / component that can implement security policies using disclosed technologies, including, for example, Palo Alto Networks' PA series next-generation firewalls, Palo Alto Networks' VM series virtualized next-generation firewalls, and CN series container next-generation firewalls, and / or other commercially available virtual-based or container-based firewalls that can be similarly implemented and configured to perform the disclosed technologies), for implementing quantum-ready security protocol algorithms and applying context-based security in the mobile network through various interfaces in the mobile network (e.g., N2, N3, N4 interfaces and / or other interfaces in the 5G core network), as further described below.
[0101] like Figure 2B As shown, each of the above 5G network access mechanisms securely communicates with the central core site / public cloud 109, which includes the 5G core network 110A, as referenced above. Figure 2A Similarly, in a second example of a service deployment architecture for a private 5G mobile network with only RAN local deployment and a quantum-ready smart security gateway 102, the 5G RAN 106A is in IPSec communication (e.g., including management plane and control plane communication via N3 and user plane communication via the N2 interface), as shown.
[0102] Therefore, service providers and / or enterprises can use the disclosed technologies and security platforms to apply quantum-ready smart security gateways.
[0103] Various example use cases for the quantum-ready smart security gateway will now be described below.
[0104] Example use cases for quantum-ready smart security gateways The disclosed techniques for providing enhanced security for mobile / service provider networks using security platforms to implement security policies (including techniques for applying context-based security using APIs and data storage) can be applied to a variety of additional example use case scenarios to facilitate enhanced security for mobile networks (e.g., 4G / 5G / 6G and beyond), as will now be described for various example use cases.
[0105] As a first example use case, in a service provider’s 4G / LTE and 5G mobile networks, a security gateway or similar device is configured to provide the following capabilities: (1) encrypting traffic, which includes a control and management plane between the 4G / 5G base station and the core mobile network; and (2) inspecting the control and management traffic for threats in order to detect and block any malicious activity, for example, based on security policies.
[0106] As a second example use case, in a service provider’s 5G mobile network, a security gateway or similar device is configured to provide the following capabilities: (1) encrypting traffic, which includes the control and management plane between the 5G base station and the core mobile network; and (2) inspecting only selected enterprise(one or more) network slice traffic for known and unknown threats (e.g., based on security policies).
[0107] As a third example use case, the disclosed technology for applying quantum-ready smart security gateways can be used in private wireless networks to encrypt traffic (including user plane, control plane, and management plane) between 4G base stations and the core mobile network. Furthermore, the quantum-ready smart security gateway can then (e.g., based on security policies) inspect all north / south user traffic for known and unknown threats.
[0108] As a fourth example use case, the disclosed technology for applying quantum-ready smart security gateways can be used in private wireless networks to encrypt traffic (including user plane, control plane, and management plane) between 5G base stations and the core mobile network. Furthermore, the quantum-ready smart security gateway can then (e.g., based on security policies) inspect all traffic, including device-to-device traffic targeting known and unknown threats.
[0109] As a fifth example use case, in a service provider’s 5G private mobile network, a security gateway or similar device is configured to provide the following capabilities: (1) encrypting traffic, including the user plane, control plane and management plane between the 5G base station and the core network; (2) inspecting all control and management traffic; and (3) offloading all video traffic, decrypting encrypted subscriber traffic, inspecting all subscriber and IoT / OT traffic other than video for known and unknown threats, and applying URL filtering to block malware, C&C, phishing, ransomware and other malicious sites (e.g., based on security policies).
[0110] As will now be clear to those skilled in the art, the disclosed technology for applying quantum-ready smart security gateways can be applied to a variety of additional example use case scenarios to detect / prevent these and other types of attacks, thereby facilitating enhanced security in various deployments and environments in mobile networks.
[0111] Example hardware components for a network device used in a quantum-ready smart security gateway Figure 3 This is a functional diagram of the hardware components of a network device for a quantum-ready smart security gateway according to some embodiments. The examples shown represent physical / hardware components that can be included in network device 300 (e.g., a device, gateway, or server that can implement the security gateway disclosed herein). Specifically, network device 300 includes a high-performance multi-core CPU 302 and RAM 304. Network device 300 also includes a storage device 310 (e.g., one or more hard disks or solid-state storage units) which can be used to store policies and other configuration information, as well as signatures. In one embodiment, storage device 310 stores certain information (e.g., subscriber-ID, device-ID, and / or network slice-ID, as well as user-ID and system log message-related / extracted parameters) extracted from monitored traffic via various interfaces (e.g., S1-U, S11, N3, N4, and / or other interfaces) monitored to implement the disclosed security policy implementation techniques for applying context-based security through various interfaces, including the disclosed techniques for applying subscriber-ID-based security, device-ID-based security, and / or network slice-ID-based security, as well as user-ID and system log messages, in mobile networks using one or more security platforms as described herein. Network device 300 may also include one or more optional hardware accelerators. For example, network device 300 may include a cryptographic engine 306 configured to perform encryption and decryption operations, and one or more FPGAs 308 configured to perform signature matching, act as a network processor, and / or perform other tasks.
[0112] Example logic components for a network device used in a quantum-ready smart security gateway Figure 4 This is a functional diagram of the logical components of a network device for a quantum-ready smart security gateway according to some embodiments. The examples shown represent logical components that may be included in network device 400 (e.g., a data device that can implement the disclosed security gateway and perform the disclosed techniques for applying subscriber-ID-based security, device-ID-based security, network slice-ID-based security with user ID, and / or other context-based security through various interfaces in a mobile network). As shown, network device 400 includes a management plane 402 and a data plane 404. In one embodiment, the management plane is responsible for managing user interactions, such as by providing a user interface for configuring policies and viewing log data. The data plane is responsible for managing data, such as by performing packet processing and session disposition.
[0113] Suppose a mobile device attempts to access a resource (e.g., a remote website / server, MEC service, IoT device, or another resource) using an encrypted session protocol such as SSL. Network processor 406 is configured to monitor packets from the mobile device and provide them to data plane 404 for processing. Flow 408 identifies packets as part of a new session and creates a new session flow. Based on flow lookup, subsequent packets are identified as belonging to that session. If applicable, SSL decryption is applied by SSL decryption engine 410 using various techniques as described herein. Otherwise, processing by SSL decryption engine 410 is omitted. Application ID (APP ID) module 412 is configured to determine what type of traffic the session involves (e.g., as referenced above). Figure 1A-1F Similar to the description of IP traffic and / or other network protocol traffic (such as GTP-U traffic) between various monitored interfaces, it identifies the user associated with the traffic flow (e.g., identifying the user ID and application-ID (APP-ID) as described herein). For example, APPID 412 can identify a GET request in received data and infer that the session requires an HTTP decoder 414. As another example, APP ID 412 can identify GTP-U session messages carrying encapsulated IP traffic from the UE (e.g., through various interfaces, such as those described above). Figure 1A-Figure 2B (similar description), and infers that the session requires a GTP-U decoder (e.g., to extract information exchanged in a GTP-U traffic session through various interfaces including various parameters, such as those mentioned above). Figure 1A-Figure 2B(Similar description). For each type of protocol, there is a corresponding decoder 414. In one embodiment, the application identifier is executed by the application identifier module (e.g., the APP ID component / engine), and the user identifier is executed by another component / engine. Based on the determination made by the APP ID 412, the packet is sent to the appropriate decoder 414. The decoder 414 is configured to assemble the packets (e.g., which may be received out of order) into the correct order, perform tokenization, and extract information (e.g., to extract various information exchanged in GTP-U traffic through various interfaces, as similarly described above and further described below). The decoder 414 also performs signature matching to determine what should be done to the packet. The SSL encryption engine 416 performs SSL encryption using the various techniques described herein, and then forwards the packet using the forwarding component 418 shown. Also as shown, the policy 420 is received and stored in the management plane 402. In one embodiment, policy enforcement (e.g., a policy may include one or more rules that can be specified using domain names and / or host / server names, and the rules may apply one or more signatures or other matching criteria or heuristics, such as various parameters / information extracted from the DPI of monitored GTP-U / IP traffic and / or monitored GTP-U / IP and / or (one or more) other protocol traffic, for security policy enforcement on subscriber / IP flows on the service provider network, such as S1-U / S11 / N2 / N3 / N4 / other interfaces, as referenced above) Figure 1A-Figure 2B Similar descriptions are used as described in this document for monitored, decrypted, identified, and decoded session traffic flows, referencing various embodiments.
[0114] Similarly, Figure 4 As shown, an interface (I / F) communicator 422 is also provided for security gateway manager / management communications. In some cases, network device 400 is used to monitor network communications of other network elements on a service provider network, and data plane 404 supports decoding of such communications (e.g., network device 400, including I / F communicator 422 and decoder 414, can be configured to monitor and / or communicate on: for example, reference point interfaces such as S1-U, S11, N2, N3, N4 and / or other interfaces where wired and wireless network traffic flows exist). Thus, network device 400 including I / F communicator 422 can be used to implement the disclosed techniques for providing a quantum-ready smart security gateway in a mobile network, as described above and as will be further described below.
[0115] Additional example procedures for the disclosed technology for quantum-ready smart security gateways will now be described.
[0116] Example procedure for a quantum-ready smart security gateway Figure 5 This is a flowchart of a process for a quantum-ready smart security gateway according to some embodiments. In some embodiments, such as Figure 5 The process 500 shown is accomplished by security gateways and technologies similar to those described above (including those referenced above). Figure 1A-Figure 2B The described embodiment is used to perform this process. In one embodiment, process 500 is performed by the above-referenced embodiment. Figure 3 The data device 300, as mentioned above (reference above) Figure 4 The network device 400, virtual devices (e.g., Palo Alto Networks' VM series virtualized next-generation firewall, CN series container next-generation firewall, and / or other commercially available virtual or container-based firewalls that can be similarly implemented and configured to perform the disclosed technologies), SDN security solutions, cloud security services, and / or combinations or hybrid implementations as described herein.
[0117] In 502, network traffic on the mobile network is monitored at the security gateway to identify new sessions. For example, in some cases, the security gateway (e.g., a firewall, a network sensor acting on behalf of the firewall, or another device / component that can implement security policies) can monitor various protocols on the mobile network (e.g., GTP-U (e.g., via S1-U, S11, N3, N4, and / or other interfaces) and / or other protocols), and more specifically, by performing the disclosed techniques, various interfaces, such as S1-U, S11, and N3, N4 interfaces, as referenced above, can be monitored. Figure 1A-Figure 2B Similarly, in an example implementation, the security gateway includes a quantum-ready smart security gateway that supports quantum key distribution (QKD) and / or post-quantum cryptography (PQC) for providing a secure tunnel to a mobile network.
[0118] In the 504 error, the process involved extracting metadata from network traffic at the security gateway via one or more interfaces to determine metadata associated with the new session. For example, determining the metadata associated with the new session could be achieved by implementing the techniques disclosed for quantum-ready smart security gateways, as referenced above. Figure 1A-Figure 2B Described similarly.
[0119] In section 506, security policies are enforced at the security gateway based on metadata to apply context-based security in the mobile network. For example, security policy enforcement may include allowing or blocking a session or performing another action based on the policy, such as those described above.
[0120] Figure 6This is another flowchart of a process for a quantum-ready smart security gateway according to some embodiments. In some embodiments, such as Figure 6 The process 600 shown is based on a security platform and technology similar to those described above (including the references above). Figures 1A-4 The described embodiment is executed. In one embodiment, process 600 is performed by the above-described reference. Figure 3 The data device 300, as mentioned above (reference above) Figure 4 The network device 400, virtual devices (e.g., Palo Alto Networks' VM series virtualized next-generation firewall, CN series container next-generation firewall, and / or other commercially available virtual or container-based firewalls that can be similarly implemented and configured to perform the disclosed technologies), SDN security solutions, cloud security services, and / or combinations or hybrid implementations as described herein.
[0121] In section 602, tunnel security for network communications to a mobile network using a secure gateway is implemented. In an example implementation, the secure gateway includes a quantum-ready smart secure gateway supporting quantum key distribution (QKD) and / or post-quantum cryptography (PQC) for providing secure tunnels to a mobile network (e.g., by implementing NIST proposals such as: FIPS 203, a modular lattice-based key encapsulation mechanism standard (available at https: / / CSRC.NIST.gov / pubs / FIPS / 203 / ipd); FIPS 204, a modular lattice-based digital signature standard (available at https: / / CSRC.NIST.gov / pubs / FIPS / 204 / ipd); and FIPS 205, a stateless hash-based digital signature standard (available at https: / / CSRC.NIST.gov / pubs / FIPS / 205 / ipd)).
[0122] In 604, monitoring network traffic on a mobile network at a security gateway is performed to identify new sessions. For example, in some cases, a security gateway (e.g., a firewall, a network sensor acting on behalf of a firewall, or another device / component that can implement security policies) can monitor various protocols on the mobile network (e.g., GTP-U (e.g., via S1-U, S11, N3, N4, and / or other interfaces) and / or other protocols), and more specifically, by performing the disclosed techniques, various interfaces, such as S1-U, S11, and N3, N4 interfaces, as referenced above, can be monitored. Figure 1A-Figure 2B Described similarly.
[0123] In 606, the process of extracting metadata from network traffic at a security gateway via one or more interfaces to determine metadata associated with a new session is performed. For example, determining the metadata associated with a new session can be achieved by implementing the disclosed techniques for quantum-ready smart security gateways, as referenced above. Figure 1A-Figure 2B Described similarly.
[0124] At 608, a security policy is enforced at the security gateway based on metadata to apply context-based security in the mobile network. For example, security policy enforcement may include allowing or blocking a session or performing another action based on the policy, such as those described above.
[0125] Although the embodiments described above have been described in some detail for clarity of understanding, the invention is not limited to the details provided. Many alternative ways of implementing the invention exist. The disclosed embodiments are illustrative and not restrictive.
Claims
1. A system comprising: Processor, the processor being configured to: Monitor network traffic on the mobile network at the security gateway to identify new sessions. Meta-information associated with the new session is determined by extracting metadata from the network traffic via one or more interfaces, and Based on the metadata, a security policy is implemented on the new session at the security gateway to apply context-based security in the mobile network; and A memory coupled to the processor and configured to provide instructions to the processor.
2. The system of claim 1, wherein the security gateway includes a quantum-ready smart security gateway supporting quantum key distribution (QKD) and / or post-quantum cryptography (PQC) for providing a secure tunnel to the mobile network.
3. The system according to claim 1, wherein the security gateway includes a quantum-ready smart security gateway, the quantum-ready smart security gateway supporting intelligent offloading of monitored network traffic based on an offloading strategy.
4. The system of claim 1, wherein the context-based security includes subscriber-ID-based security.
5. The system of claim 1, wherein the context-based security includes device-ID-based security.
6. The system of claim 1, wherein the context-based security includes network slice-ID-based security.
7. The system of claim 1, wherein the security gateway is configured with multiple security policies to apply subscriber-ID-based security, device-ID-based security, and / or network slice-ID-based security in the mobile network.
8. The system according to claim 1, wherein the security gateway is configured with multiple security policies to apply vulnerability protection, intrusion prevention, antivirus, anti-spyware, DNS security, denial-of-service (DoS) protection, and / or cloud-based security.
9. The system of claim 1, wherein the processor is further configured to: Perform level threat identification and prevention in mobile networks.
10. The system of claim 1, wherein the processor is further configured to: Perform application identification and control in mobile networks.
11. The system of claim 1, wherein the processor is further configured to: Perform URL filtering on mobile networks.
12. The system of claim 1, wherein the processor is further configured to: New sessions are prevented from accessing resources based on security policies.
13. The system of claim 1, wherein the processor is further configured to: New sessions are allowed to access resources based on security policies.
14. A method comprising: Monitor network traffic on the mobile network at the security gateway to identify new sessions; Meta-information associated with a new session is determined by extracting metadata from network traffic via one or more interfaces; and Security policies are implemented for new sessions at the security gateway based on metadata, enabling context-based security to be applied in mobile networks.
15. The method of claim 14, wherein the security gateway comprises a quantum-ready smart security gateway supporting quantum key distribution (QKD) and / or post-quantum cryptography (PQC) for providing a secure tunnel to the mobile network.
16. The method of claim 14, wherein the security gateway includes a quantum-ready smart security gateway, the quantum-ready smart security gateway supporting intelligent offloading of monitored network traffic based on an offloading policy.
17. The method of claim 14, wherein the security gateway is configured with a plurality of security policies to apply subscriber-ID-based security, device-ID-based security and / or network slice-ID-based security in the mobile network.
18. The method of claim 14, wherein the security gateway is configured with multiple security policies to apply vulnerability protection, intrusion prevention, antivirus, anti-spyware, DNS security, denial-of-service (DoS) protection, and / or cloud-based security.
19. A computer program product embodied in a non-transitory computer-readable storage medium and comprising computer instructions for: Monitor network traffic on the mobile network at the security gateway to identify new sessions; Meta-information associated with a new session is determined by extracting metadata from network traffic via one or more interfaces; and Security policies are implemented for new sessions at the security gateway based on metadata, enabling context-based security to be applied in mobile networks.
20. The computer program product of claim 19, wherein the security gateway includes a quantum-ready smart security gateway supporting quantum key distribution (QKD) and / or post-quantum cryptography (PQC) for providing a secure tunnel to the mobile network.
Citation Information
Patent Citations
Distributed offload leveraging different offload devices
US11665139B2