Cloud-Based 5G Security Steering for MEC Workloads

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration of cloud-based security services into 5G networks is challenging due to the need for secure and efficient data processing and management across diverse edge computing environments, particularly in scenarios where data does not require cloud transit, and existing solutions do not adequately address workload isolation and security for edge-hosted applications.

Innovation Solution

The integration of cloud-based security services within Multiaccess Edge Compute (MEC) systems, utilizing intelligent steering to direct traffic to the most effective edge for processing, and secure edge steering through dynamic, unique, and encrypted tunnels, ensuring authorized access and protection regardless of edge location or latency, leveraging SIM/eSIM/iSIM for IoT devices and APN networks for secure connectivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cloud-based security services are integrated into MEC systems, then security coverage for edge-hosted workloads is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments security functions by separating cloud-based security services from edge computing workloads. The cloud-based security service provider operates independently from MEC hosts, with security enforcement points deployed at strategic locations (data centers, regional centers) rather than within each edge device. This segmentation allows security coverage to extend to edge workloads without embedding complex security functions within the edge devices themselves.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary security enforcement points that act as mediators between edge workloads and the cloud. These enforcement points, deployed at data centers and regional communication centers, serve as intermediaries that forward traffic requiring security processing to the cloud-based security service provider. This intermediary architecture enables security coverage for edge workloads while maintaining simple edge device architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If all data traffic is routed through cloud-based security services, then security inspection is improved, but network latency increases

Engineering Contradiction:
Improvesecurity inspectionVSAvoidnetwork latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system applies partial action by selectively routing only specific data traffic through cloud-based security services rather than all traffic. The MEC host forwards traffic to the cloud-based security service provider only when security inspection is required, allowing low-latency operations to proceed directly at the edge without unnecessary security processing steps. This partial routing approach balances security inspection effectiveness with network latency minimization.

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If edge workloads are made accessible to authorized entities, then service availability is improved, but security risk increases

Engineering Contradiction:
Improveservice availabilityVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts security access control functions from the edge workload infrastructure and places them in the cloud-based security service provider. The MEC host and edge workloads remain simple and focused on computing tasks, while the cloud-based system handles authentication, authorization, and security policy enforcement. This extraction allows authorized access to edge workloads without compromising the simplicity and security of the edge infrastructure itself.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If MEC hosts forward traffic to cloud-based security services, then security processing capability is improved, but network bandwidth consumption increases

Engineering Contradiction:
Improvesecurity processing capabilityVSAvoidnetwork bandwidth
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system implements partial action by having MEC hosts forward only the portions of traffic that require security processing to the cloud-based security service provider. Traffic that does not require security inspection remains local at the edge, avoiding unnecessary bandwidth consumption. The selective forwarding approach based on traffic characteristics and security policies ensures that network bandwidth is used efficiently for security processing only where necessary.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12010553B2Cloud-based 5G security network architectures with intelligent steering
Publication Date: 2024.06.11 ZSCALER INC
  • US12010553B2 patent drawing
  • US12010553B2 patent drawing
  • US12010553B2 patent drawing

AI summary

Cloud-based 5G security, implemented in a Multi-Access Edge Compute (MEC) system, includes steps of receiving a request for a workload from User Equipment (UE); determining a type of traffic for the workflow and querying a machine learning engine based on the traffic type; informing the UE of how the workflow should be accessed; and receiving an updated request for the workflow and steering the traffic based on how the workflow should be steered. The steps can include receiving policy updates from a cloud-based system, related to how workloads should be steered.