5G LAN Session Security Using Context-Based Network Parameters

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing 5G networks face challenges in securing 5G LAN-type services for user equipment devices, requiring improved security techniques for monitoring network traffic and applying context-based security policies.

Innovation Solution

A system and process for 5G LAN security in mobile networks that involves monitoring network traffic, extracting 5G LAN-related parameters using APIs, and enforcing security policies based on these parameters to provide 5G LAN-level threat identification, prevention, and control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewall rules are used for 5G network security, then basic access control is provided, but context-based security policies cannot be effectively enforced

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the parameters used for security decision-making from traditional static firewall rules to dynamic 5G LAN-related parameters including session ID, DNN (data network name), S-NSSAI (slice identifier), and 5G-GUTI (5G identification). This parameter transformation enables context-based security policies to be enforced while maintaining manageable system complexity through structured data collection and processing.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If network traffic monitoring is enhanced for 5G LAN security, then threat identification capability is improved, but processing overhead increases

Engineering Contradiction:
Improvethreat identificationVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts only the necessary 5G LAN-related parameters from the full network traffic data for security policy enforcement. Instead of processing entire packet contents, the system extracts specific fields such as session identifiers, network slice information, and user equipment identifiers, significantly reducing processing overhead while maintaining effective threat identification capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs preliminary action by pre-establishing security policies and parameter extraction rules before actual traffic monitoring begins. The security function is configured with predefined policy frameworks that specify which parameters to monitor and how to interpret them, reducing real-time processing requirements and enabling efficient threat detection.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If 5G LAN-related parameters are collected and processed, then context-based security policies can be enforced, but system complexity increases

Engineering Contradiction:
Improvecontext-based security policyVSAvoidparameter processing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal security function that handles multiple security tasks using the same 5G LAN parameter set. The collected parameters (session ID, DNN, S-NSSAI, 5G-GUTI) serve multiple purposes including authentication, authorization, traffic routing, and security policy enforcement, eliminating the need for separate processing systems for each function and reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20260082230A1Performing 5g LAN security based on 5g LAN related parameters
Publication Date: 2026.03.19 PALO ALTO NETWORKS INC
  • US20260082230A1 patent drawing
  • US20260082230A1 patent drawing
  • US20260082230A1 patent drawing

AI summary

Techniques for 5G LAN security in mobile networks are disclosed. In some embodiments, a system/process/computer program product for 5G LAN security in mobile networks includes monitoring network traffic on a mobile network at a security platform to identify a new session; extracting a plurality of 5G LAN related parameters using an application programming interface (API) at the security platform; and enforcing a security policy on the new session at the security platform based on one or more of the plurality of 5G LAN related parameters to apply 5G LAN security in the mobile network.