Network Slice Security Platform for 5G Dynamic Policy Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current service provider networks face challenges in implementing dynamic and endpoint-specific security policies for wireless devices, requiring network infrastructure updates for policy changes, which is inefficient and inflexible.

Innovation Solution

The implementation of network slice-based security platforms in 5G mobile networks using HTTP/2 message parsing to extract S-NSSAI, SUPI, PEI, GPSI, and User Location information for applying security policies dynamically, enabling per-subscriber and per-device security management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional firewall policies are used in mobile networks, then network security is provided, but the security policies are static and require network infrastructure updates for policy changes

Engineering Contradiction:
Improvesecurity policy flexibilityVSAvoidnetwork infrastructure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments security policies into network slice-specific policies, where each slice (e.g., eMBB, URLLC, MIoT) has its own dedicated security policy set. This allows independent management and dynamic adjustment of policies for different service types without affecting the entire network infrastructure, resolving the contradiction by enabling flexibility at the slice level while maintaining manageable complexity through modular organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic security policies that can be adjusted in real-time based on network conditions, device type, and service requirements. The security platform can dynamically modify firewall rules, access control lists, and other security parameters without requiring physical infrastructure changes, thereby achieving policy flexibility while avoiding the complexity of hardware updates.

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If network slice-based security is implemented, then dynamic and endpoint-specific security policies are enabled, but HTTP/2 message parsing and multiple information extractions are required

Engineering Contradiction:
Improvesecurity policy managementVSAvoidsecurity platform complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The security platform is designed with multi-functional capabilities to handle various extraction tasks (S-NSSAI, SUPI, PEI, GPSI, User Location) through a unified HTTP/2 message parsing mechanism. This universal approach consolidates multiple security management functions into a single platform, making security policy management easier while the modular architecture keeps the platform complexity manageable through standardized processing routines.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary security platform that sits between the network infrastructure and end devices, handling the complex tasks of message parsing and information extraction. This intermediary absorbs the processing complexity, presenting a simplified interface for security policy management to operators while performing the detailed technical work of extracting multiple parameters from HTTP/2 messages.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If per-subscriber and per-device security management is implemented, then real-time threat detection and prevention are improved, but network traffic monitoring and analysis requirements increase

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork processing resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by implementing security monitoring and threat detection at the network slice level and even at the individual device level within slices. Instead of uniform network-wide monitoring, security resources are concentrated where needed based on the specific security requirements of each slice and device, improving overall security reliability while optimizing the use of processing resources by avoiding redundant monitoring in low-risk areas.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP4080918B1Network slice-based security in mobile networks
Publication Date: 2024.08.14 PALO ALTO NETWORKS INC
  • EP4080918B1 patent drawingFigure 1A
  • EP4080918B1 patent drawingFigure 1B
  • EP4080918B1 patent drawingFigure 1C

AI summary

Techniques for providing network slice-based security in mobile networks (e.g., service provider networks for mobile subscribers) are disclosed. In some embodiments, a system/process/computer program product for network slice-based security in mobile networks in accordance with some embodiments includes monitoring network traffic on a service provider network at a security platform to identify a new session, wherein the service provider network includes a 5G network or a converged 5G network; extracting network slice information for user traffic associated with the new session at the security platform; and determining a security policy to apply at the security platform to the new session based on the network slice information.