Edge Workload Security Steering via MEC Integration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
5G wireless deployments face increased security risks due to the expansion of network traffic volumes and the use of unsecured, unmanaged devices, as traditional security measures are inadequate for protecting workloads running on 5G networks, and existing cloud-based security solutions do not effectively integrate with Multiaccess Edge Compute (MEC) systems to manage traffic between User Equipment (UE) and edge devices.
Innovation Solution
Integrating cloud-based security services within service providers' MECs, enabling intelligent steering of traffic to the most effective edge for processing and securing, using SIM/eSIM/iSIM-based approaches for secure edge steering, and implementing dynamic, unique, and encrypted tunnels for workload isolation and access, independent of underlying mobile network transports.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cloud-based security services are integrated within MECs, then security coverage for edge workloads is improved, but device complexity increases
Solution Approach 1:
The patent merges cloud-based security services with MEC infrastructure by integrating security functions (firewall, intrusion detection, data loss prevention) directly into the edge computing platform. This consolidation provides comprehensive security coverage for edge workloads while managing complexity through unified architecture where security and computing functions share infrastructure resources.
Solution Approach 2:
The MEC platform is designed to perform multiple functions simultaneously - computing, storage, networking, and security - through a universal architecture. The security services operate as additional functional layers on top of existing MEC components, enabling one system to handle both workloads without requiring separate dedicated security infrastructure.
2Ease of manufacture
If traditional security measures are used for 5G networks, then implementation simplicity is maintained, but security effectiveness deteriorates
Solution Approach 1:
The patent introduces cloud-based security services as an intermediary layer between user equipment and edge workloads. This intermediary provides advanced security functions (deep packet inspection, threat intelligence, data loss prevention) that go beyond traditional perimeter security, effectively addressing the security effectiveness gap while maintaining implementation simplicity through service-oriented architecture.
Solution Approach 2:
The system transitions from static, perimeter-based security parameters to dynamic, context-aware security parameters. Security policies are continuously adjusted based on user identity, device posture, workload sensitivity, and real-time threat intelligence, enabling effective security adaptation without complex manual configuration.
3Reliability
If all data traffic is backhauled to the cloud for security processing, then security coverage is improved, but network latency increases
Solution Approach 1:
The patent segments security processing into two parts: local security functions executed at the MEC edge for low-latency requirements, and cloud-based security services for comprehensive analysis. Critical workloads can have security processing performed locally at the edge, while less time-sensitive traffic is sent to the cloud, optimizing the balance between security coverage and latency.
Solution Approach 2:
The system dynamically determines where security processing should occur based on workload characteristics, data sensitivity, and network conditions. Flexible policy enforcement points can be dynamically positioned between edge and cloud, allowing the system to adapt the security processing location in real-time to minimize latency while maintaining adequate security coverage.
Data Source
AI summary
The present disclosure relates to systems and methods for cloud-based 5G security network architectures intelligent steering, workload isolation, identity, and secure edge steering. Specifically, various approaches are described to integrate cloud-based security services into Multiaccess Edge Compute servers (MECs). That is, existing cloud-based security services are in line between a UE and the Internet. The present disclosure includes integrating the cloud-based security services and associated cloud-based system within service provider's MECs. In this manner, a cloud-based security service can be integrated with a service provider's 5G network or a 5G network privately operated by the customer. For example, nodes in a cloud-based system can be collocated within a service provider's network, to provide security functions to 5G users or connected by peering from the cloud-based security service into the 5G service provider's regional communications centers.


