Zero Trust Security Platform for 5G Mobile Networks Using PFCP

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security solutions for mobile networks lack effective mechanisms for implementing intelligent security for zero trust, particularly in environments with perimeter security platforms, which are preferred by service providers and enterprises due to complexity and control issues.

Innovation Solution

The implementation of a system that deploys security platforms in 5G and 4G/LTE mobile networks, utilizing protocols such as PFCP, Radius, and Diameter, to monitor and process messages for extracting contextual information from User Equipment (UE) and applying security policies based on this information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If perimeter security platforms are deployed in mobile networks, then control and security policy enforcement are improved, but device complexity and integration difficulty increase

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidplatform integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security platform is segmented into modular components including PFCP message processing modules, security policy enforcement modules, and contextual information extraction modules. This segmentation allows independent deployment and management of security functions, reducing integration complexity while maintaining enforcement capability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security platform acts as an intermediary between the mobile network infrastructure and security policies. It intercepts and processes PFCP messages between network elements, providing a standardized interface for security enforcement without requiring deep integration into core network elements

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If context-based security is implemented by monitoring PFCP messages, then security precision and threat identification are improved, but information processing load and time increase

Engineering Contradiction:
Improvecontext extraction accuracyVSAvoidmessage processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary extraction of contextual information from PFCP messages as they arrive, maintaining a cached repository of user and session context. This preliminary action allows rapid security decisions without repeated full-message analysis, reducing processing time while maintaining extraction accuracy

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system replaces deep packet inspection and complex message parsing with PFCP protocol-aware processing that leverages the structured format of PFCP messages. This substitution enables efficient extraction of contextual information (user identity, session parameters, location) without the computational overhead of traditional deep inspection methods

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If security platforms monitor multiple protocols (PFCP, Radius, Diameter), then security coverage and adaptability are improved, but device complexity and operational difficulty increase

Engineering Contradiction:
Improveprotocol support coverageVSAvoidplatform configuration complexity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The security platform is designed with universal protocol support for PFCP, Radius, and Diameter protocols through a unified architecture. A single platform instance can monitor and enforce security policies across multiple protocol types simultaneously, eliminating the need for separate specialized devices and simplifying operational management

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250142337A1Intelligent security for zero trust in mobile networks with security platforms using a packet forwarding control protocol
Publication Date: 2025.05.01 PALO ALTO NETWORKS INC
  • US20250142337A1 patent drawing
  • US20250142337A1 patent drawing
  • US20250142337A1 patent drawing

AI summary

Techniques for applying intelligent security for zero trust in mobile networks with perimeter security platforms using a packet forwarding control protocol (PFCP) are disclosed. In some embodiments, a system/process/computer program product for applying intelligent security for zero trust in mobile networks with perimeter security platforms (e.g., using the PFCP protocol) includes deploying a security platform in a 5G and/or 4G/LTE mobile network environment, and monitoring PFCP messages at the security platform in a standalone 5G network and/or 4G/LTE network (e.g., with a CUPS architecture). Specifically, the security platform is configured to process PFCP messages including PFCP session establishment request/response messages and/or PFCP session modification request/response messages to extract contextual information, which can include User Equipment (UE) IP, International Mobile Subscription Identity (IMSI)/Subscription Permanent Identifier (SUPI), IMEI/PEI, S-NSSAI, APN/DNN, and/or RAT Type information. The security platform is further configured to apply a security policy (e.g., enforce one or more security rules) based on the contextual information.