5G Edge Security Platform for Dynamic Per-Endpoint Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile network environments for service providers face challenges in implementing dynamic and endpoint-specific security policies, particularly in wireless networks, where static security policies are applied uniformly, lacking the ability to define policies per endpoint or flow, and requiring infrastructure updates for changes.
Innovation Solution
The implementation of network slice-based and service-based security platforms that parse HTTP/2 messages to extract identifiers like S-NSSAI, SUPI, PEI, GPSI, and DNN, enabling security policies to be applied dynamically and specifically to each endpoint or flow within 5G networks, utilizing Next Generation Firewalls (NGFWs) and network sensors to monitor and filter traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If static security policies are applied uniformly across the network, then implementation is simple and infrastructure updates are minimized, but the ability to define policies per endpoint or flow is lost and security flexibility deteriorates
Solution Approach 1:
The patent segments security policies into network slice-specific policies, allowing different security rules to be applied to different slices (e.g., eMBB, URLLC, mMTC) within the same 5G network. This enables per-endpoint and per-flow security control while maintaining manageable complexity through organized policy groups.
Solution Approach 2:
The patent implements dynamic security policies that can be modified and updated without requiring infrastructure changes. The security platform allows service providers to define, deploy, and update security policies dynamically based on network conditions, endpoint requirements, and threat levels, resolving the contradiction between flexibility and complexity.
2Reliability
If infrastructure updates are required for security policy changes, then security can be updated, but network downtime increases and service continuity is disrupted
Solution Approach 1:
The patent implements a security policy management system that allows policies to be pre-configured, validated, and staged before deployment. This preliminary action ensures that security updates can be applied without disrupting ongoing network services, maintaining service continuity while enabling easy policy deployment.
Solution Approach 2:
The patent introduces a security platform as an intermediary between policy administrators and the network infrastructure. This intermediary manages policy deployment, translation, and enforcement without requiring direct infrastructure updates, thereby maintaining service continuity while simplifying security policy deployment.
3Measurement precision
If per-endpoint security policies are implemented, then security precision is improved, but the complexity of policy management and processing overhead increases
Solution Approach 1:
The patent adds the network slice dimension to security policy management, allowing policies to be defined at multiple levels (slice-level, endpoint-level, flow-level). This multi-dimensional approach enables precise per-endpoint security while managing complexity through hierarchical policy organization and automated rule generation.
Data Source
AI summary
Techniques for providing multi-access distributed edge security in mobile networks (e.g., service provider networks for mobile subscribers, such as for 5G networks) are disclosed. In some embodiments, a system/process/computer program product for multi-access distributed edge security in mobile networks in accordance with some embodiments includes monitoring network traffic on a service provider network at a security platform to identify a new session, wherein the service provider network includes a 5G network or a converged 5G network; extracting subscription and/or equipment identifier information for user traffic associated with the new session at the security platform; and determining a security policy to apply at the security platform to the new session based on the subscription and/or equipment identifier information.


