5G Edge Security Platform Dynamic Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current service provider networks in mobile environments lack dynamic security policies that can be applied on a per endpoint and per flow basis for wireless devices, requiring network infrastructure updates for policy changes, which is inefficient and poses security challenges.
Innovation Solution
Implementing network slice-based and service-based security platforms that parse HTTP/2 messages to extract relevant identifiers and apply security policies dynamically, using identifiers like S-NSSAI, SUPI, PEI, and GPSI to provide enhanced security services in 5G networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional firewall policies are used in mobile networks, then network security is provided, but security policies cannot be dynamically applied on a per endpoint and per flow basis, requiring network infrastructure updates for policy changes
Solution Approach 1:
The patent segments security policies into granular per-endpoint and per-flow basis controls, allowing different security rules to be applied to different devices and traffic flows independently. This enables dynamic policy application without requiring comprehensive network infrastructure updates, as policies can be modified at the application layer rather than requiring changes to the underlying network infrastructure.
Solution Approach 2:
The patent implements dynamic security policies that can be applied in real-time based on subscription identifiers and equipment identifiers. The system allows security policies to be dynamically created, modified, and applied without requiring network infrastructure updates, enabling flexible response to changing security requirements while maintaining a stable network infrastructure.
2Productivity
If network infrastructure updates are required for security policy changes, then comprehensive security coverage is maintained, but policy implementation efficiency decreases and security response time increases
Solution Approach 1:
The patent introduces an intermediary security platform that sits between the network infrastructure and endpoint devices. This intermediary receives security policies, parses HTTP/2 messages to extract identifiers, and applies policies dynamically without requiring changes to the core network infrastructure. This maintains comprehensive security coverage while enabling rapid policy implementation and response.
Solution Approach 2:
The patent performs preliminary parsing of HTTP/2 messages to extract subscription and equipment identifiers before security policy application. This preliminary action enables the system to pre-configure and dynamically apply appropriate security policies based on identified endpoints and flows, improving implementation efficiency while ensuring comprehensive coverage through pre-validation of security requirements.
3Measurement precision
If per endpoint and per flow security policies are implemented, then security precision is improved, but system complexity and computational overhead increase
Solution Approach 1:
The patent segments security policy enforcement into distinct per-endpoint and per-flow components, allowing precise security controls to be applied at each level independently. This segmentation enables high security precision by treating different endpoints and traffic flows with appropriate granular policies, while managing complexity through modular architecture where each segment can be configured and maintained separately.
Solution Approach 2:
The patent uses identifier extraction from HTTP/2 messages to create simplified representations of endpoints and flows. By copying and parsing key identifiers (subscription identifiers, equipment identifiers) from message headers, the system achieves precise policy application without requiring complex deep inspection of entire message contents, reducing computational overhead while maintaining security precision.
Data Source
Figure 1A
Figure 1B
Figure 1C
AI summary
Techniques for providing multi-access distributed edge security in mobile networks (e.g., service provider networks for mobile subscribers, such as for 5G networks) are disclosed. In some embodiments, a system/process/computer program product for multi-access distributed edge security in mobile networks in accordance with some embodiments includes monitoring network traffic on a service provider network at a security platform to identify a new session, wherein the service provider network includes a 5G network or a converged 5G network; extracting subscription and/or equipment identifier information for user traffic associated with the new session at the security platform; and determining a security policy to apply at the security platform to the new session based on the subscription and/or equipment identifier information.