Mobile Access Gateway Offloading Traffic to Security Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile data traffic offloading technologies struggle to accommodate the exponential growth in mobile data traffic, particularly in providing network security services, as offloaded traffic is not subjected to necessary security checks for malicious software, viruses, and malware.

Innovation Solution

Implementing a method that identifies mobile nodes on cellular networks, sends traffic offloading messages to a security as a service server, and routes traffic flows to a cloud-based security device for inspection, using a mobile access gateway and local mobility anchor in a Proxy Mobile IPv6 domain, ensuring security policies are applied to IP flows.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If mobile data traffic is offloaded to complementary networks using conventional technologies, then bandwidth and service costs are improved, but network security services deteriorate because offloaded traffic is not subjected to necessary security checks

Engineering Contradiction:
ImprovebandwidthVSAvoidnetwork security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a security gateway as an intermediary component between the offloaded traffic and the complementary network. This security gateway performs security checks (malware detection, content filtering, spam filtering) on offloaded traffic before it reaches the complementary network, thus maintaining security services while allowing traffic offloading to proceed. The security gateway acts as a mediator that enables both high bandwidth utilization and reliable security protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of energy

If mobile data traffic is offloaded to complementary networks, then operational costs are reduced, but security monitoring and control capabilities worsen

Engineering Contradiction:
Improveoperational costsVSAvoidsecurity monitoring capability
Core Design Contradiction:
Loss of energyVSDifficulty of detecting and measuring

Solution Approach 1:

The security gateway serves as an intermediary monitoring point that enables security detection and control of offloaded traffic. By positioning the security gateway in the traffic path, the system can inspect and control offloaded content without requiring complex infrastructure changes in the complementary network, thus maintaining security monitoring capabilities while benefiting from reduced operational costs of traffic offloading.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary security checks at the security gateway before traffic is fully offloaded to the complementary network. This preliminary action ensures that malicious content is filtered out in advance, maintaining security monitoring capabilities while allowing legitimate traffic to be offloaded cost-effectively to complementary networks.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2910036B1Offloaded security as a service
Publication Date: 2019.10.30 CISCO TECHNOLOGY INC
  • EP2910036B1 patent drawingFigure 1
  • EP2910036B1 patent drawingFigure 2
  • EP2910036B1 patent drawingFigure 3

AI summary

In one implementation, traffic in a mobile network is offloaded to a security as a service server or a cloud server. A mobile access gateway (MAG) in the mobile network identifies one or more mobile nodes that are configured for communication on the mobile network. The MAG receives a message that includes an address of a mobile node and sends a request based on the message to the security as a service server. The MAG forwards traffic flows to the security as a service server according to the message, which is configured to detect an indication of malicious software in the traffic flows and/or filter content of the traffic flows according to a user profile.