Mobile Core API Data Ingestion for Context-Based Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile networks, such as 5G and 4G/LTE, lack visibility and context-based security due to inaccessible interfaces, preventing effective deployment of security platforms like NGFWs, and mobile service providers are hesitant to deploy these due to latency and service outage concerns.

Innovation Solution

Utilizing Application Programming Interfaces (APIs) to extract parameters from mobile core network entities, determine session context, and apply security policies without altering existing mobile network configurations, enabling context-aware and real-time security actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security platforms like NGFWs are deployed in mobile networks, then context-based security is improved, but latency and service outage risks increase

Engineering Contradiction:
Improvecontext-based securityVSAvoidlatency
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent introduces an intermediary system that collects mobile network data through standardized interfaces and makes it available to security platforms via APIs. This mediator approach allows security functions to be added without directly modifying the mobile network core, thereby avoiding latency and service outage issues while still enabling context-based security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the security function from the mobile network core by using separate data collection points and API interfaces. Instead of deploying security platforms within the mobile network core (which would cause latency), the system collects data at network edges and provides it to security platforms through standardized interfaces, separating security processing from network traffic paths.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If existing mobile network configurations are modified to enable security platforms, then visibility and context awareness are improved, but network complexity and deployment difficulty increase

Engineering Contradiction:
Improvevisibility into mobile networkVSAvoidnetwork configuration changes
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent enables mobile network entities to self-provide data through their existing standardized interfaces without requiring external modifications. The network entities themselves expose their data via APIs, eliminating the need for complex configuration changes while maintaining full visibility and context awareness capabilities.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent uses universal standardized interfaces and APIs that can be implemented across different mobile network entities without requiring network-specific custom configurations. These universal interfaces allow any mobile network entity to provide data to security platforms through a common mechanism, reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If data collection and context determination are performed in real-time, then security response speed is improved, but system resource consumption increases

Engineering Contradiction:
Improvesecurity response speedVSAvoidsystem resource consumption
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The patent performs preliminary data collection and caching of mobile network entity data, so that when security events occur, the necessary context information is already available for immediate processing. This pre-positioning of data enables fast security responses without requiring real-time resource-intensive data collection at the moment of incident response.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250260722A1Enabling device context awareness, data ingestion and real-time actions in mobile networks
Publication Date: 2025.08.14 PALO ALTO NETWORKS INC
  • US20250260722A1 patent drawing
  • US20250260722A1 patent drawing
  • US20250260722A1 patent drawing

AI summary

Techniques for data ingestion enabling context awareness and real-time actions in mobile networks are disclosed. In some embodiments, a system, a process, and/or a computer program product for data ingestion enabling context awareness and real-time actions in mobile networks includes extracting a plurality of parameters from a mobile core network entity using an application programming interface (API) call, messages over a message broker, and/or logs from the mobile core network entity; determining a context for a session using one or more of the plurality of parameters associated with a mobile device communicating over the mobile core network; and applying a security policy using a security platform to the session based on the context.