Mobile Access Gateway Offloading Traffic to Security Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile data traffic offloading technologies struggle to accommodate the exponential growth in mobile data traffic, particularly in providing network security services, as offloaded traffic is not subjected to necessary security checks for malicious software, viruses, and malware.
Innovation Solution
Implementing a method that identifies mobile nodes on cellular networks, sends traffic offloading messages to a security as a service server, and routes traffic flows to a cloud-based security device for inspection, using a mobile access gateway and local mobility anchor in a Proxy Mobile IPv6 domain, ensuring security policies are applied to IP flows.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If mobile data traffic is offloaded to complementary networks using conventional technologies, then bandwidth and service costs are improved, but network security services deteriorate because offloaded traffic is not subjected to necessary security checks
Solution Approach 1:
The patent introduces a security gateway as an intermediary component between the offloaded traffic and the complementary network. This security gateway performs security checks (malware detection, content filtering, spam filtering) on offloaded traffic before it reaches the complementary network, thus maintaining security services while allowing traffic offloading to proceed. The security gateway acts as a mediator that enables both high bandwidth utilization and reliable security protection.
2Loss of energy
If mobile data traffic is offloaded to complementary networks, then operational costs are reduced, but security monitoring and control capabilities worsen
Solution Approach 1:
The security gateway serves as an intermediary monitoring point that enables security detection and control of offloaded traffic. By positioning the security gateway in the traffic path, the system can inspect and control offloaded content without requiring complex infrastructure changes in the complementary network, thus maintaining security monitoring capabilities while benefiting from reduced operational costs of traffic offloading.
Solution Approach 2:
The system performs preliminary security checks at the security gateway before traffic is fully offloaded to the complementary network. This preliminary action ensures that malicious content is filtered out in advance, maintaining security monitoring capabilities while allowing legitimate traffic to be offloaded cost-effectively to complementary networks.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
In one implementation, traffic in a mobile network is offloaded to a security as a service server or a cloud server. A mobile access gateway (MAG) in the mobile network identifies one or more mobile nodes that are configured for communication on the mobile network. The MAG receives a message that includes an address of a mobile node and sends a request based on the message to the security as a service server. The MAG forwards traffic flows to the security as a service server according to the message, which is configured to detect an indication of malicious software in the traffic flows and/or filter content of the traffic flows according to a user profile.