5G Edge Security Platform for Dynamic Per-Endpoint Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile network environments for service providers face challenges in implementing dynamic and endpoint-specific security policies, particularly in wireless networks, where static security policies are applied uniformly, lacking the ability to define policies per endpoint or flow, and requiring infrastructure updates for changes.

Innovation Solution

The implementation of network slice-based and service-based security platforms that parse HTTP/2 messages to extract identifiers like S-NSSAI, SUPI, PEI, GPSI, and DNN, enabling security policies to be applied dynamically and specifically to each endpoint or flow within 5G networks, utilizing Next Generation Firewalls (NGFWs) and network sensors to monitor and filter traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If static security policies are applied uniformly across the network, then implementation is simple and infrastructure updates are minimized, but the ability to define policies per endpoint or flow is lost and security flexibility deteriorates

Engineering Contradiction:
Improvesecurity policy flexibilityVSAvoidsecurity platform complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments security policies into network slice-specific policies, allowing different security rules to be applied to different slices (e.g., eMBB, URLLC, mMTC) within the same 5G network. This enables per-endpoint and per-flow security control while maintaining manageable complexity through organized policy groups.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic security policies that can be modified and updated without requiring infrastructure changes. The security platform allows service providers to define, deploy, and update security policies dynamically based on network conditions, endpoint requirements, and threat levels, resolving the contradiction between flexibility and complexity.

Inventive Principle:
Principle #15Dynamics

2Reliability

If infrastructure updates are required for security policy changes, then security can be updated, but network downtime increases and service continuity is disrupted

Engineering Contradiction:
Improveservice continuityVSAvoidsecurity policy deployment
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent implements a security policy management system that allows policies to be pre-configured, validated, and staged before deployment. This preliminary action ensures that security updates can be applied without disrupting ongoing network services, maintaining service continuity while enabling easy policy deployment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a security platform as an intermediary between policy administrators and the network infrastructure. This intermediary manages policy deployment, translation, and enforcement without requiring direct infrastructure updates, thereby maintaining service continuity while simplifying security policy deployment.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If per-endpoint security policies are implemented, then security precision is improved, but the complexity of policy management and processing overhead increases

Engineering Contradiction:
Improvesecurity policy precisionVSAvoidpolicy management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent adds the network slice dimension to security policy management, allowing policies to be defined at multiple levels (slice-level, endpoint-level, flow-level). This multi-dimensional approach enables precise per-endpoint security while managing complexity through hierarchical policy organization and automated rule generation.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11019077B2Multi-access distributed edge security in mobile networks
Publication Date: 2021.05.25 PALO ALTO NETWORKS INC
  • US11019077B2 patent drawing
  • US11019077B2 patent drawing
  • US11019077B2 patent drawing

AI summary

Techniques for providing multi-access distributed edge security in mobile networks (e.g., service provider networks for mobile subscribers, such as for 5G networks) are disclosed. In some embodiments, a system/process/computer program product for multi-access distributed edge security in mobile networks in accordance with some embodiments includes monitoring network traffic on a service provider network at a security platform to identify a new session, wherein the service provider network includes a 5G network or a converged 5G network; extracting subscription and/or equipment identifier information for user traffic associated with the new session at the security platform; and determining a security policy to apply at the security platform to the new session based on the subscription and/or equipment identifier information.