Mobile SASE Security Gateway Integration for Unmanaged Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need for improved integration of mobile devices with Secure Access Service Edge (SASE) solutions to provide enhanced security in mobile networks, particularly for 4G, 5G, and 6G devices, as existing SASE solutions lack effective monitoring and intelligent security for zero trust in mobile network environments.
Innovation Solution
A SASE solution that monitors network traffic and applies intelligent security for zero trust by using context-based information such as subscriber-ID, equipment-ID, and radio access technology to facilitate secure data plane traffic for mobile devices, without requiring security equipment in the mobile core network, and supports seamless integration across geo-locations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing SASE solutions are used without mobile network integration, then device deployment is simple, but security monitoring and threat identification capabilities are insufficient
Solution Approach 1:
The patent merges SASE security functions with mobile core network elements by integrating a security gateway into the UPF (User Plane Function) and establishing direct communication between the SMF (Session Management Function) and the security gateway. This integration combines the simplicity of cloud-based SASE with the monitoring capabilities of the mobile network, resolving the contradiction between simple deployment and effective security monitoring.
Solution Approach 2:
The security gateway acts as an intermediary component that bridges the mobile core network and the SASE cloud service. It receives context information from the SMF, performs local security policies enforcement, and communicates with the cloud security service, thereby enabling enhanced monitoring without requiring complete system redesign.
2Measurement precision
If context-based security policies are enforced with detailed subscriber and equipment information, then security precision is improved, but information processing overhead increases
Solution Approach 1:
The system performs preliminary actions by having the SMF provide context information (subscriber-ID, equipment-ID, location, etc.) to the security gateway in advance before actual data traffic flows. This allows the security gateway to pre-establish security policies and context mappings, reducing real-time processing overhead while maintaining high precision in policy enforcement.
3Reliability
If security equipment is deployed in the mobile core network, then threat identification capability is enhanced, but network infrastructure complexity increases
Solution Approach 1:
The security gateway is designed as a multi-functional element that combines UPF capabilities with security enforcement functions. It can perform packet inspection, threat identification, context-based policy enforcement, and communication with both the mobile core network (SMF) and cloud security services, thereby enhancing threat identification without requiring separate dedicated security devices for each function.
4Reliability
If zero trust security model is implemented with continuous verification, then security reliability is improved, but processing time and latency increase
Solution Approach 1:
The system establishes security contexts and policies in advance during session setup, before actual data traffic requires verification. The SMF provides context information to the security gateway upfront, enabling the gateway to make rapid policy decisions during data plane operations without repeated authentication delays, thus maintaining zero trust reliability while minimizing latency.
Data Source
AI summary
Techniques for providing security for providing a Secure Access Service Edge (SASE) solution for enhanced security for unmanaged devices for mobile networks (e.g., service provider networks for mobile subscribers) are disclosed. In some embodiments, various techniques to apply per network slice security for unmanaged devices in mobile networks with SASE are disclosed. In some embodiments, various techniques to apply per subscriber identity and/or equipment identity and/or subscriber number security for unmanaged devices in mobile networks with SASE are disclosed. In some embodiments, various techniques to apply per access point name/data network name (APN/DNN) security for unmanaged devices in mobile networks with SASE are disclosed. In some embodiments, various techniques to apply per location security for unmanaged devices in mobile networks with SASE are disclosed. In some embodiments, various techniques to apply per Radio Access Technology (RAT) security for unmanaged devices in mobile networks with SASE are disclosed.


