NG-RAN and O-RAN Interface Security Using Traffic Context

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The NG-RAN and O-RAN architectures in mobile networks introduce new security threats through interfaces like Xn-U and F1-U, which are vulnerable to attacks from compromised self-driving cars and IoT devices, necessitating improved context-based security solutions for network traffic monitoring and policy application.

Innovation Solution

Implementing a security platform that performs stateful inspection and context-based security on Xn-C, Xn-U, F1-C, and F1-U interfaces by extracting contextual information from traffic protocols like XnAP and F1AP, and applying layer-7 security on GTP-U traffic to enforce policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If basic firewall filtering is applied to network traffic, then network security is provided, but security policies cannot be enforced on encrypted or application-layer traffic

Engineering Contradiction:
Improvenetwork securityVSAvoidsecurity platform complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a next-generation firewall as an intermediary security platform positioned between network segments. This firewall performs deep packet inspection, application identification, and policy enforcement on traffic flows without requiring endpoint security software on each device. The firewall mediates security functions centrally, enabling enforcement of security policies on both encrypted and unencrypted traffic at the network level while maintaining compatibility with existing network infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If deep packet inspection is performed to identify applications and enforce security policies, then security policy enforcement is improved, but processing time and system resources increase

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidtraffic processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The next-generation firewall performs preliminary classification and identification of traffic flows during the connection establishment phase. Application signatures and protocols are recognized early in the traffic flow, allowing the firewall to pre-determine applicable security policies before full packet inspection is required. This preliminary action reduces processing time for subsequent packets in the same flow while maintaining accurate application identification and policy enforcement.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If next-generation firewall with application identification is deployed, then application-level security control is achieved, but device complexity and deployment difficulty increase

Engineering Contradiction:
Improveapplication-level security controlVSAvoidfirewall system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The next-generation firewall integrates multiple security functions into a single unified platform: traditional packet filtering, deep packet inspection, application identification, intrusion prevention, and policy enforcement. This multi-functional design eliminates the need for separate security devices for each function, reducing overall system complexity while providing comprehensive application-level security control. The unified interface and centralized management simplify deployment and configuration compared to multiple specialized security appliances.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP4483535B1Context-based security over interfaces in NG-ran environments and o-ran environments in mobile networks
Publication Date: 2026.04.01 PALO ALTO NETWORKS INC
  • EP4483535B1 patent drawingFigure 1
  • EP4483535B1 patent drawingFigure 2A
  • EP4483535B1 patent drawingFigure 2B

AI summary

Techniques for applying context-based security over interfaces in O-RAN environments in mobile networks are disclosed. In some embodiments, a system/process/computer program product for applying context-based security over interfaces in O-RAN environments in mobile networks includes monitoring network traffic on a mobile network at a security platform to identify a GTP-U tunnel session setup message associated with a new session; extracting a plurality of parameters from the GTP-U tunnel session setup message and from F1AP traffic to extract contextual information at the security platform; and enforcing a security policy at the security platform on the new session based on one or more of the plurality of parameters to apply context-based security to the network traffic transported between O-RAN Distributed Unit (O-DU) and O-RAN Centralized Unit Control Plane (O-CU- CP) nodes in an O-RAN environment in the mobile network. Techniques for applying context-based security over interfaces in NG-RAN environments in mobile networks are also disclosed. In some embodiments, a system/process/computer program product for applying context-based security over interfaces in NG-RAN environments in mobile networks includes monitoring network traffic on a mobile network at a security platform to identify a GTP-U tunnel session setup message associated with a new session; extracting a plurality of parameters from the GTP-U tunnel session setup message and from XnAP traffic to extract contextual information at the security platform; and enforcing a security policy at the security platform on the new session based on one or more of the plurality of parameters to apply context-based security to the network traffic transported between NG-RAN nodes in an NG-RAN environment in the mobile network.