5G Security Platform Dynamic Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current service provider networks in mobile environments lack dynamic security solutions that can apply security policies on a per endpoint or per flow basis for wireless devices, requiring network infrastructure updates for policy changes, which is inefficient and poses security challenges.

Innovation Solution

Implementing network slice-based security platforms that parse HTTP/2 messages to extract relevant information, such as S-NSSAI, SUPI, PEI, GPSI, and User Location, to apply security policies dynamically within 5G networks, using Next Generation Firewalls (NGFWs) and network sensors to monitor and filter traffic based on these identifiers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional firewalls are used in mobile networks, then network security is provided, but security policies cannot be applied dynamically per endpoint or per flow basis

Engineering Contradiction:
Improvesecurity policy flexibilityVSAvoidpolicy update efficiency
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent segments security policies into granular units that can be applied per endpoint, per flow, or per session based on extracted identifiers (SUPI, PEI, GPSI). This segmentation enables dynamic policy application without requiring network-wide updates, resolving the contradiction between policy flexibility and update efficiency.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements dynamic security policies that can be applied in real-time based on user identification and location information extracted from HTTP/2 messages. Policies can be modified and applied to specific users or sessions without network infrastructure updates, enabling adaptability while maintaining operational efficiency.

Inventive Principle:
Principle #15Dynamics

2Reliability

If network infrastructure updates are required for policy changes, then security coverage is maintained, but network productivity decreases due to frequent updates

Engineering Contradiction:
Improvesecurity coverageVSAvoidnetwork update frequency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces an intermediary security platform that sits between the network infrastructure and users, extracting identification information from HTTP/2 messages and applying security policies independently of network infrastructure updates. This intermediary layer maintains security coverage while eliminating the need for frequent network updates.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates virtual copies of security policy enforcement at the application layer through HTTP/2 message interception and analysis. Instead of updating physical network infrastructure, the solution copies security functionality to the software layer, maintaining reliability while improving productivity.

Inventive Principle:
Principle #26Copying

3Measurement precision

If per-user security policies are implemented, then security precision is improved, but device complexity increases

Engineering Contradiction:
Improveuser identification accuracyVSAvoidsecurity platform complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent changes the parameter of user identification from generic network addresses to specific identifiers (SUPI, PEI, GPSI) extracted from HTTP/2 messages. This parameter change enables precise per-user policy application while the automated extraction process manages complexity by standardizing the identification mechanism.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10812972B2Service-based security per user location in mobile networks
Publication Date: 2020.10.20 PALO ALTO NETWORKS INC
  • US10812972B2 patent drawing
  • US10812972B2 patent drawing
  • US10812972B2 patent drawing

AI summary

Techniques for providing service-based security per user location in mobile networks (e.g., service provider networks for mobile subscribers) are disclosed. In some embodiments, a system/process/computer program product for service-based security per user location in mobile networks in accordance with some embodiments includes monitoring network traffic on a service provider network at a security platform to identify a new session, wherein the service provider network includes a 5G network or a converged 5G network; extracting user location information for user traffic associated with the new session at the security platform; and determining a security policy to apply at the security platform to the new session based on the user location information.