Network Cybersecurity Service Provisioning via Dynamic Policy Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile networks lack the flexibility to provide cybersecurity services on-demand, as these services are typically pre-selected and pre-configured, limiting their adaptability to user needs and security policies.

Innovation Solution

A system that automates the provisioning of cybersecurity services by a network, utilizing a database of operator security policies and a Cybersecurity Control function to manage the selection and configuration of security services for User Equipment, allowing for dynamic configuration and placement of security functions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security services are pre-selected and pre-configured at design time, then network security functions are established, but flexibility and adaptability to user needs are limited

Engineering Contradiction:
Improvenetwork security function establishmentVSAvoidflexibility to user needs
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security service provisioning where the network can select and configure security services in real-time based on user requests, operator policies, and current network conditions. The system transitions from static pre-configured services to dynamic on-demand services, allowing the security architecture to adapt flexibly to changing user needs while maintaining reliable security functions through automated policy-based configuration.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If security services are provided as a service by the network on-demand, then flexibility and user adaptability increase, but system complexity increases

Engineering Contradiction:
Improveon-demand service provisioningVSAvoidprovisioning system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where the network automatically provisions security services based on user requests and operator policies without manual intervention. The system uses automated policy evaluation, service selection, and configuration processes that enable on-demand service delivery while managing complexity through automation. The network itself performs the provisioning tasks, reducing the need for complex manual configuration processes.

Inventive Principle:
Principle #25Self-service

3Reliability

If security functions are dynamically configured and placed by the network, then protection against attacks is enhanced, but provisioning complexity increases

Engineering Contradiction:
Improveprotection against attacksVSAvoiddynamic configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements feedback mechanisms where the network continuously monitors security conditions, user requests, and policy requirements to dynamically adjust security service configuration and placement. The system uses policy-based decision-making that evaluates current network state and automatically configures appropriate security functions. This feedback-driven approach enhances attack protection by adapting security measures to current threats while managing complexity through structured policy evaluation rather than ad-hoc configuration.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12225059B2Providing cybersecurity services by a network and automated provisioning thereof
Publication Date: 2025.02.11 ORANGE SA
  • US12225059B2 patent drawing
  • US12225059B2 patent drawing
  • US12225059B2 patent drawing

AI summary

Systems and methods for providing cybersecurity services by a network and for automating the provisioning of the cybersecurity services are disclosed. The system comprises a connection control function configured to receive a message in response to a request to establish a data connection from a user equipment (UE), the message including a requested CyberSecurity Control service identifier (CSC-ID) corresponding to a first security service of a plurality of security services. The CCF can interact with a cybersecurity control (CSC) function to determine, based on the requested CSC-ID, an allowed CSC-ID for the data connection, the allowed CSC-ID corresponding to a second security service of the plurality of security services; retrieve, based on the allowed CSC-ID, an operator security policy associated with the second security service. The CCF can then select and configure a network function in accordance with the retrieved operator security policy associated with the second security service.