Mobile Network SASE Gateway for Context-Based Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for improved integration of mobile networks with Secure Access Service Edge (SASE) solutions, particularly for seamless authentication and authorization in mobile network environments, and for applying intelligent security using context-based information for mobile devices communicating over service provider networks.

Innovation Solution

A system/process/computer program product for applying intelligent security for zero trust using a Service Access Service Edge (SASE) solution, which includes receiving traffic from a mobile core network at a SASE cloud network, enforcing security policies based on contextual information, and forwarding secured data plane traffic to its original destination, without requiring security equipment in the service provider's core mobile networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security equipment is deployed in service provider's core mobile networks, then security enforcement capability is improved, but device complexity and integration difficulty increase

Engineering Contradiction:
Improvesecurity enforcement capabilityVSAvoidintegration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a SASE gateway as an intermediary component that bridges the mobile core network and the SASE cloud service. This gateway receives traffic from the mobile core network, applies security policies, and forwards traffic to the SASE cloud for enforcement, thereby eliminating the need to deploy complex security equipment directly within the service provider's core network while maintaining security capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If context-based security policies are enforced on mobile network traffic, then security effectiveness is improved, but processing time and system complexity increase

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by extracting contextual information from mobile network traffic and caching security policy decisions before actual traffic enforcement. The SASE gateway pre-processes traffic to identify contextual parameters (such as user identity, device characteristics, location) and prepares corresponding security policies in advance, reducing processing time during actual traffic flow while maintaining effective context-based security enforcement.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If multiple enterprise networks are managed separately, then network security control is improved, but management complexity and operational overhead increase

Engineering Contradiction:
Improvenetwork security controlVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a unified SASE cloud service that provides multi-functional security management capabilities for multiple enterprise networks. The system offers centralized policy management, authentication, and security enforcement that can be applied across different enterprise networks through a single platform, eliminating the need for separate management systems while maintaining granular security control for each enterprise.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250323948A1Secure access service edge for mobile networks
Publication Date: 2025.10.16 PALO ALTO NETWORKS INC
  • US20250323948A1 patent drawing
  • US20250323948A1 patent drawing
  • US20250323948A1 patent drawing

AI summary

Techniques for providing security for providing Secure Access Service Edge (SASE) for mobile networks (e.g., service provider networks for mobile subscribers) are disclosed. In some embodiments, a system/process/computer program product for providing SASE for mobile networks in accordance with some embodiments includes receiving traffic associated with a User Equipment (UE) from a mobile core network at a SASE cloud network; enforcing a security policy on data plane traffic associated with the UE based on contextual information associated with the UE to provide secured data plane traffic; and forwarding the secured data plane traffic from the SASE cloud network to its original destination.