Network Slice Security Platform for 5G Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile network environments for service providers lack dynamic security solutions that can apply security policies on a per endpoint or per flow basis, requiring network infrastructure updates for policy changes, which is inefficient and poses security challenges.

Innovation Solution

Implementing network slice-based security platforms that parse HTTP/2 messages to extract relevant information, such as S-NSSAI, SUPI, PEI, and GPSI, to apply security policies dynamically within 5G networks, enabling enhanced security services like threat detection and prevention, URL filtering, and application DoS management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If static security policies are used in mobile networks, then network infrastructure remains stable and simple, but security cannot be dynamically adjusted per endpoint or per flow

Engineering Contradiction:
Improvesecurity policy flexibilityVSAvoidnetwork infrastructure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the network into multiple network slices, each with its own security policies. This allows different security configurations to be applied to different slices (e.g., IoT slice, mobile broadband slice) without affecting the entire network, enabling dynamic security adjustment while maintaining infrastructure stability through standardized slice management mechanisms

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a security gateway as an intermediary component that sits between the network core and access networks. This gateway dynamically enforces security policies based on endpoint and flow characteristics, providing adaptability without requiring changes to the core network infrastructure, thus resolving the contradiction between flexibility and complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If network infrastructure is updated frequently to change security policies, then security adaptability improves, but network stability and operational efficiency deteriorate

Engineering Contradiction:
Improvesecurity policy update capabilityVSAvoidnetwork operation efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent implements dynamic security policies that can be adjusted in real-time based on network conditions, endpoint behavior, and threat levels. The security gateway dynamically modifies policy enforcement without requiring infrastructure updates, allowing security adaptability while maintaining network operational efficiency through software-based policy management rather than hardware changes

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If per endpoint security policies are implemented, then security precision improves, but processing overhead and system complexity increase

Engineering Contradiction:
Improvesecurity policy granularityVSAvoidpolicy management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates virtual copies of security policy enforcement instances for different network slices and endpoints. The security gateway uses virtualization to replicate policy enforcement capabilities across multiple endpoints simultaneously, enabling per-endpoint security management without proportionally increasing physical infrastructure complexity, as virtual instances can be deployed and managed through centralized control

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11792235B2Network slice-based security in mobile networks
Publication Date: 2023.10.17 PALO ALTO NETWORKS INC
  • US11792235B2 patent drawing
  • US11792235B2 patent drawing
  • US11792235B2 patent drawing

AI summary

Techniques for providing network slice-based security in mobile networks (e.g., service provider networks for mobile subscribers) are disclosed. In some embodiments, a system/process/computer program product for network slice-based security in mobile networks in accordance with some embodiments includes monitoring network traffic on a service provider network at a security platform to identify a new session, wherein the service provider network includes a 5G network or a converged 5G network; extracting network slice information for user traffic associated with the new session at the security platform; and determining a security policy to apply at the security platform to the new session based on the network slice information.