5G LAN Session Security Using Context-Based Network Parameters
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing 5G networks face challenges in securing 5G LAN-type services for user equipment devices, requiring improved security techniques for monitoring network traffic and applying context-based security policies.
Innovation Solution
A system and process for 5G LAN security in mobile networks that involves monitoring network traffic, extracting 5G LAN-related parameters using APIs, and enforcing security policies based on these parameters to provide 5G LAN-level threat identification, prevention, and control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional firewall rules are used for 5G network security, then basic access control is provided, but context-based security policies cannot be effectively enforced
Solution Approach 1:
The patent changes the parameters used for security decision-making from traditional static firewall rules to dynamic 5G LAN-related parameters including session ID, DNN (data network name), S-NSSAI (slice identifier), and 5G-GUTI (5G identification). This parameter transformation enables context-based security policies to be enforced while maintaining manageable system complexity through structured data collection and processing.
2Reliability
If network traffic monitoring is enhanced for 5G LAN security, then threat identification capability is improved, but processing overhead increases
Solution Approach 1:
The patent extracts only the necessary 5G LAN-related parameters from the full network traffic data for security policy enforcement. Instead of processing entire packet contents, the system extracts specific fields such as session identifiers, network slice information, and user equipment identifiers, significantly reducing processing overhead while maintaining effective threat identification capability.
Solution Approach 2:
The patent performs preliminary action by pre-establishing security policies and parameter extraction rules before actual traffic monitoring begins. The security function is configured with predefined policy frameworks that specify which parameters to monitor and how to interpret them, reducing real-time processing requirements and enabling efficient threat detection.
3Adaptability or versatility
If 5G LAN-related parameters are collected and processed, then context-based security policies can be enforced, but system complexity increases
Solution Approach 1:
The patent implements a universal security function that handles multiple security tasks using the same 5G LAN parameter set. The collected parameters (session ID, DNN, S-NSSAI, 5G-GUTI) serve multiple purposes including authentication, authorization, traffic routing, and security policy enforcement, eliminating the need for separate processing systems for each function and reducing overall system complexity.
Data Source
AI summary
Techniques for 5G LAN security in mobile networks are disclosed. In some embodiments, a system/process/computer program product for 5G LAN security in mobile networks includes monitoring network traffic on a mobile network at a security platform to identify a new session; extracting a plurality of 5G LAN related parameters using an application programming interface (API) at the security platform; and enforcing a security policy on the new session at the security platform based on one or more of the plurality of 5G LAN related parameters to apply 5G LAN security in the mobile network.


