Mobile Embedded Security Platform for SASE Bootstrap and User Visibility
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Corporate IT departments face challenges in obtaining visibility into remote users' activities and achieving dynamic granular access control over public and private networks, as existing technologies lack integration of secure access service edge (SASE) and support for GBA/AKMA, leading to difficulties in managing secure connectivity and visibility across diverse user environments.
Innovation Solution
Implementing a mobile embedded security platform (MESyP) that integrates GBA/AKMA and SASE technologies, leveraging eSIM/iSIM profiles, and supporting VPN control planes to manage UE-specific bootstrap configurations, enabling secure connectivity over public and private networks with end-to-end encryption and centralized supervision.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If VPN tunnels are setup between users' devices and remote dedicated VPN gateways, then secure connectivity is achieved, but visibility into remote users' activities is lost
Solution Approach 1:
The patent introduces a cloud-based management platform as an intermediary between users and corporate networks. This platform provides a portal that gives IT administrators visibility into user activities, device status, and security events without compromising the security of the VPN connection. The intermediary enables monitoring and control functions that were previously lost in traditional VPN architectures.
2Loss of information
If logs are collected from different corporate applications to improve visibility, then user activity monitoring is enhanced, but system complexity increases
Solution Approach 1:
The patent implements a universal cloud-based management platform that consolidates multiple monitoring and management functions into a single system. Instead of collecting logs from different applications separately, the platform provides a unified interface for IT administrators to monitor user activities, manage devices, control security policies, and view security events across all corporate applications and networks, thereby reducing system complexity.
3Reliability
If dynamic granular access control is implemented for different users, applications, times, and locations, then security control is improved, but device complexity increases
Solution Approach 1:
The patent implements a self-service portal that allows users to autonomously manage their own access requests, device configurations, and security settings. Users can register their devices, request access to specific applications, and manage their profiles without requiring complex manual configuration by IT administrators. This self-service approach enables dynamic granular access control while reducing the operational complexity of managing such controls.
Data Source
AI summary
A method performed by a computer-implemented controller is provided. The method includes receiving a request for managing one or more user equipments (UEs); obtaining a user-specific security profile from a first service provider; obtaining a subscriber identity module (SIM) profile from a network node or a second service provider; obtaining a set of secure access service edge (SASE) instances from the network node; building one or more UE-specific bootstrap configurations based on the user-specific security profile, the SIM profile, and the set of SASE instances; and sending the one or more UE-specific bootstrap configurations to a third service provider. The one or more UE-specific bootstrap configurations are obtainable by the one or more UEs to establish a secured wireless communication channel through a zero-trusted network.


