RAT-Based Security Policy Enforcement in Service Provider Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Service provider networks face challenges in implementing dynamic and location-based security policies for wireless devices, as they cannot currently define security policies on a per-endpoint or per-flow basis, nor can they utilize hardware attributes or location information for wireless devices communicating over their networks.
Innovation Solution
The implementation of a security platform that monitors GPRS Tunneling Protocol (GTP) communications to apply security policies based on parameters such as application, IP address, content ID, subscriber location, unique device identifiers, and Radio Access Technology (RAT) using next-generation firewalls, allowing for real-time, granular security policy enforcement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional firewalls are used to protect service provider networks, then basic network security is provided, but dynamic and location-based security policies cannot be implemented
Solution Approach 1:
The patent implements dynamic security policies that can be applied in real-time based on changing conditions such as device location, RAT type, and threat level. The security platform continuously monitors network parameters and automatically adjusts security policies without requiring manual reconfiguration, making the system adaptive to evolving threats and network conditions.
Solution Approach 2:
The security platform segments security policies into granular rules that can be applied to specific devices, locations, applications, or network flows. This segmentation allows the system to handle complex security requirements by breaking them down into manageable, independently configurable policy elements that can be selectively applied.
2Reliability
If granular security policies per endpoint and per-flow are implemented, then enhanced security control is achieved, but system complexity increases
Solution Approach 1:
The security platform provides a unified system that handles multiple security functions simultaneously - device identification, location tracking, RAT detection, threat analysis, and policy enforcement - all through a single platform. This multi-functionality reduces the need for separate specialized systems while maintaining granular control capabilities.
Solution Approach 2:
The system automatically performs device identification, location determination, and threat assessment without requiring manual intervention. Security policies are automatically applied based on real-time monitoring of network parameters, reducing the operational complexity of managing granular security rules.
3Measurement precision
If hardware attributes and location information are utilized for security policies, then precise security enforcement is possible, but information processing requirements increase
Solution Approach 1:
The security platform extracts only the essential identifying parameters from device communications - such as device identifiers, location information, and RAT type - and uses these extracted features for policy enforcement. This selective extraction reduces the processing burden by focusing only on relevant information rather than analyzing all device data.
Solution Approach 2:
The system performs device identification, location determination, and RAT detection during the initial connection establishment phase, before full data processing begins. By completing these information-gathering tasks preliminarily, the system avoids the need to continuously process and analyze all device data throughout the connection lifecycle.
Data Source
AI summary
Techniques for radio access technology based security in service provider networks (e.g., service provider networks for mobile subscribers) are disclosed. In some embodiments, a system/process/computer program product for radio access technology based security in service provider networks includes monitoring network traffic on a service provider network at a security platform to identify a Radio Access Technology (RAT) type for a new session; associating the RAT type with the new session at the security platform; and determining a security policy to apply at the security platform to the new session based on the RAT type.


