Network Slice Routing for Edge Security Without Session Slowdown
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wireless communication networks often fail to effectively or efficiently facilitate communication between wireless network slices and edge-based security services like SASE, leading to a tradeoff between session performance and security, which degrades the user experience.
Innovation Solution
A method and communication network architecture that enables enhanced network slice security by routing user data from qualified devices to edge security services for policy enforcement, utilizing control and user planes to select and update network slices for secure data transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If network slices route user data directly to data networks without edge security services, then session performance is improved, but security is degraded
Solution Approach 1:
The patent segments the network data flow into control plane signaling and user plane data, and further segments user plane traffic into authenticated/unauthenticated and secured/unsecured flows. This segmentation allows different routing paths: authenticated traffic requiring security enforcement is routed to edge security services, while other traffic maintains direct paths for optimal performance.
Solution Approach 2:
The patent introduces edge security services as an intermediary component between network slices and data networks. The intermediary selectively enforces security policies on specific traffic flows based on authentication status and policy rules, rather than forcing all traffic through security enforcement, thus balancing security requirements with performance optimization.
2Reliability
If network slices route user data through edge security services for security enforcement, then security is improved, but session performance is degraded
Solution Approach 1:
The patent applies local quality by making security enforcement selective rather than universal. Edge security services enforce security policies locally on specific traffic flows that require protection (e.g., unauthenticated traffic, traffic from untrusted networks), while allowing other traffic to bypass security enforcement and maintain optimal performance.
Solution Approach 2:
The patent implements partial action by applying security enforcement only to the extent necessary - specifically to traffic flows that require security protection based on authentication status and policy rules. This partial enforcement avoids the performance degradation that would result from enforcing security on all traffic, while still providing adequate security where needed.
3Reliability
If network slices are updated to route traffic to edge security services, then security policy enforcement is improved, but network complexity is increased
Solution Approach 1:
The patent implements dynamic network slicing where slice configurations can be updated in real-time based on security requirements, user authentication status, and policy rules. The network dynamically adjusts routing paths between network slices and edge security services without requiring manual reconfiguration, allowing flexible security policy enforcement while maintaining operational simplicity.
Solution Approach 2:
The patent incorporates feedback mechanisms where the control plane receives information about user device authentication status, security policy requirements, and traffic characteristics. Based on this feedback, the control plane automatically updates network slice configurations and routing paths to edge security services, enabling adaptive security enforcement without increasing operational complexity.
Data Source
AI summary
Various embodiments include a communication network that comprises a control plane and a user plane. The control plane selects a network slice for the user device in response to a session request for a user device. The session request identifies the network slice. The control plane indicates the network slice to the user device. The control plane determines the user device qualifies for enhanced slice security. The control plane updates the network slice to route user data for the user device on the network slice to an edge security service in response to determining the user device qualifies for the enhanced slice security. The user plane exchanges the user data with the user device over the network slice. The user plane routes the user data to the edge security service. The edge security service enforces security policies on the user data and delivers the user data to a data network.


