5G Security Platform Dynamic Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current service provider networks in mobile environments lack dynamic security solutions that can apply security policies on a per endpoint or per flow basis for wireless devices, requiring network infrastructure updates for policy changes, which is inefficient and poses security challenges.
Innovation Solution
Implementing network slice-based security platforms that parse HTTP/2 messages to extract relevant information, such as S-NSSAI, SUPI, PEI, GPSI, and User Location, to apply security policies dynamically within 5G networks, using Next Generation Firewalls (NGFWs) and network sensors to monitor and filter traffic based on these identifiers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional firewalls are used in mobile networks, then network security is provided, but security policies cannot be applied dynamically per endpoint or per flow basis
Solution Approach 1:
The patent segments security policies into granular units that can be applied per endpoint, per flow, or per session based on extracted identifiers (SUPI, PEI, GPSI). This segmentation enables dynamic policy application without requiring network-wide updates, resolving the contradiction between policy flexibility and update efficiency.
Solution Approach 2:
The system implements dynamic security policies that can be applied in real-time based on user identification and location information extracted from HTTP/2 messages. Policies can be modified and applied to specific users or sessions without network infrastructure updates, enabling adaptability while maintaining operational efficiency.
2Reliability
If network infrastructure updates are required for policy changes, then security coverage is maintained, but network productivity decreases due to frequent updates
Solution Approach 1:
The patent introduces an intermediary security platform that sits between the network infrastructure and users, extracting identification information from HTTP/2 messages and applying security policies independently of network infrastructure updates. This intermediary layer maintains security coverage while eliminating the need for frequent network updates.
Solution Approach 2:
The system creates virtual copies of security policy enforcement at the application layer through HTTP/2 message interception and analysis. Instead of updating physical network infrastructure, the solution copies security functionality to the software layer, maintaining reliability while improving productivity.
3Measurement precision
If per-user security policies are implemented, then security precision is improved, but device complexity increases
Solution Approach 1:
The patent changes the parameter of user identification from generic network addresses to specific identifiers (SUPI, PEI, GPSI) extracted from HTTP/2 messages. This parameter change enables precise per-user policy application while the automated extraction process manages complexity by standardizing the identification mechanism.
Data Source
AI summary
Techniques for providing service-based security per user location in mobile networks (e.g., service provider networks for mobile subscribers) are disclosed. In some embodiments, a system/process/computer program product for service-based security per user location in mobile networks in accordance with some embodiments includes monitoring network traffic on a service provider network at a security platform to identify a new session, wherein the service provider network includes a 5G network or a converged 5G network; extracting user location information for user traffic associated with the new session at the security platform; and determining a security policy to apply at the security platform to the new session based on the user location information.


