Mobile Core Security Policy Mapping from GTP Location Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Service providers in today's networks face challenges in implementing dynamic security policies based on hardware attributes or location information for wireless devices, limiting their ability to monitor and enforce security policies on a per endpoint or per flow basis.

Innovation Solution

A security platform is configured to monitor GTP communications between network elements in mobile core networks, extracting parameters like IMEI, IMSI, and location to apply granular security policies in real-time, using next-generation firewalls for enhanced security enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional firewalls are used with static rules, then network access control is provided, but dynamic security policies based on location or hardware attributes cannot be implemented

Engineering Contradiction:
Improvedynamic security policy implementationVSAvoidsecurity platform complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic security policies by extracting location information (TAI, LAC, RAI) and device identifiers (IMEI, IMSI) from GTP-C messages to create time-varying security rules. The system transitions from static firewall rules to dynamic policies that adapt to user location and device characteristics, enabling location-based access control and device-specific security measures.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces a security platform as an intermediary component between the existing GTP-C signaling path and the firewall. This intermediary extracts location and device parameters from GTP-C messages, determines security policies, and modifies firewall rules accordingly, enabling dynamic security without requiring fundamental changes to the core network architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If per endpoint or per flow security monitoring is implemented, then network security is improved, but existing network architecture does not support such granular monitoring

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts location information (TAI, LAC, RAI) and device identifiers (IMEI, IMSI) from the existing GTP-C signaling messages. By taking out these parameters from the signaling flow, the system enables granular security monitoring and per-flow policy enforcement without disrupting the core network signaling architecture or requiring additional signaling protocols.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent makes the GTP-C message format universal by utilizing existing fields for multiple purposes: location tracking, device identification, and security policy determination. This multi-functionality approach enables per-endpoint and per-flow security monitoring while maintaining backward compatibility with existing network elements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If location-based security policies are applied, then security enforcement is improved, but extraction and processing of location parameters adds processing overhead

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidsignal processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs location parameter extraction and security policy determination in advance during the PDP context activation phase, before user data traffic begins. By preparing security rules beforehand based on extracted location and device information, the system minimizes processing overhead during actual data transmission and enables rapid security enforcement.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4054120B1Location based security in service provider networks
Publication Date: 2026.03.04 PALO ALTO NETWORKS INC
  • EP4054120B1 patent drawingFigure 1A
  • EP4054120B1 patent drawingFigure 1B
  • EP4054120B1 patent drawingFigure 2A

AI summary

Techniques for location based security in service provider networks (e.g., service provider networks for mobile subscribers) are disclosed. In some embodiments, a system/process/computer program product for location based security in service provider networks includes monitoring network traffic on a service provider network at a security platform to identify a location for a new session; associating the location with the new session at the security platform; and determining a security policy to apply at the security platform to the new session based on the location.