Mobile Core Security Policy Mapping from GTP Location Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Service providers in today's networks face challenges in implementing dynamic security policies based on hardware attributes or location information for wireless devices, limiting their ability to monitor and enforce security policies on a per endpoint or per flow basis.
Innovation Solution
A security platform is configured to monitor GTP communications between network elements in mobile core networks, extracting parameters like IMEI, IMSI, and location to apply granular security policies in real-time, using next-generation firewalls for enhanced security enforcement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional firewalls are used with static rules, then network access control is provided, but dynamic security policies based on location or hardware attributes cannot be implemented
Solution Approach 1:
The patent implements dynamic security policies by extracting location information (TAI, LAC, RAI) and device identifiers (IMEI, IMSI) from GTP-C messages to create time-varying security rules. The system transitions from static firewall rules to dynamic policies that adapt to user location and device characteristics, enabling location-based access control and device-specific security measures.
Solution Approach 2:
The patent introduces a security platform as an intermediary component between the existing GTP-C signaling path and the firewall. This intermediary extracts location and device parameters from GTP-C messages, determines security policies, and modifies firewall rules accordingly, enabling dynamic security without requiring fundamental changes to the core network architecture.
2Reliability
If per endpoint or per flow security monitoring is implemented, then network security is improved, but existing network architecture does not support such granular monitoring
Solution Approach 1:
The patent extracts location information (TAI, LAC, RAI) and device identifiers (IMEI, IMSI) from the existing GTP-C signaling messages. By taking out these parameters from the signaling flow, the system enables granular security monitoring and per-flow policy enforcement without disrupting the core network signaling architecture or requiring additional signaling protocols.
Solution Approach 2:
The patent makes the GTP-C message format universal by utilizing existing fields for multiple purposes: location tracking, device identification, and security policy determination. This multi-functionality approach enables per-endpoint and per-flow security monitoring while maintaining backward compatibility with existing network elements.
3Reliability
If location-based security policies are applied, then security enforcement is improved, but extraction and processing of location parameters adds processing overhead
Solution Approach 1:
The patent performs location parameter extraction and security policy determination in advance during the PDP context activation phase, before user data traffic begins. By preparing security rules beforehand based on extracted location and device information, the system minimizes processing overhead during actual data transmission and enables rapid security enforcement.
Data Source
Figure 1A
Figure 1B
Figure 2A
AI summary
Techniques for location based security in service provider networks (e.g., service provider networks for mobile subscribers) are disclosed. In some embodiments, a system/process/computer program product for location based security in service provider networks includes monitoring network traffic on a service provider network at a security platform to identify a location for a new session; associating the location with the new session at the security platform; and determining a security policy to apply at the security platform to the new session based on the location.