Network Slice Security Platform for 5G Dynamic Policy Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current service provider networks face challenges in implementing dynamic and endpoint-specific security policies for wireless devices, requiring network infrastructure updates for policy changes, which is inefficient and inflexible.
Innovation Solution
The implementation of network slice-based security platforms in 5G mobile networks using HTTP/2 message parsing to extract S-NSSAI, SUPI, PEI, GPSI, and User Location information for applying security policies dynamically, enabling per-subscriber and per-device security management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional firewall policies are used in mobile networks, then network security is provided, but the security policies are static and require network infrastructure updates for policy changes
Solution Approach 1:
The patent segments security policies into network slice-specific policies, where each slice (e.g., eMBB, URLLC, MIoT) has its own dedicated security policy set. This allows independent management and dynamic adjustment of policies for different service types without affecting the entire network infrastructure, resolving the contradiction by enabling flexibility at the slice level while maintaining manageable complexity through modular organization.
Solution Approach 2:
The patent implements dynamic security policies that can be adjusted in real-time based on network conditions, device type, and service requirements. The security platform can dynamically modify firewall rules, access control lists, and other security parameters without requiring physical infrastructure changes, thereby achieving policy flexibility while avoiding the complexity of hardware updates.
2Ease of operation
If network slice-based security is implemented, then dynamic and endpoint-specific security policies are enabled, but HTTP/2 message parsing and multiple information extractions are required
Solution Approach 1:
The security platform is designed with multi-functional capabilities to handle various extraction tasks (S-NSSAI, SUPI, PEI, GPSI, User Location) through a unified HTTP/2 message parsing mechanism. This universal approach consolidates multiple security management functions into a single platform, making security policy management easier while the modular architecture keeps the platform complexity manageable through standardized processing routines.
Solution Approach 2:
The patent introduces an intermediary security platform that sits between the network infrastructure and end devices, handling the complex tasks of message parsing and information extraction. This intermediary absorbs the processing complexity, presenting a simplified interface for security policy management to operators while performing the detailed technical work of extracting multiple parameters from HTTP/2 messages.
3Reliability
If per-subscriber and per-device security management is implemented, then real-time threat detection and prevention are improved, but network traffic monitoring and analysis requirements increase
Solution Approach 1:
The patent applies local quality by implementing security monitoring and threat detection at the network slice level and even at the individual device level within slices. Instead of uniform network-wide monitoring, security resources are concentrated where needed based on the specific security requirements of each slice and device, improving overall security reliability while optimizing the use of processing resources by avoiding redundant monitoring in low-risk areas.
Data Source
Figure 1A
Figure 1B
Figure 1C
AI summary
Techniques for providing network slice-based security in mobile networks (e.g., service provider networks for mobile subscribers) are disclosed. In some embodiments, a system/process/computer program product for network slice-based security in mobile networks in accordance with some embodiments includes monitoring network traffic on a service provider network at a security platform to identify a new session, wherein the service provider network includes a 5G network or a converged 5G network; extracting network slice information for user traffic associated with the new session at the security platform; and determining a security policy to apply at the security platform to the new session based on the network slice information.