SASE Security Gateway for Context-Aware Mobile Network Slices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for improved integration of mobile networks with Secure Access Service Edge (SASE) solutions, particularly for mobile devices, to enhance security and apply intelligent security for zero trust in mobile network environments.

Innovation Solution

A SASE solution that monitors network traffic and applies intelligent security for zero trust by using contextual information such as subscriber-ID, equipment-ID, subscriber number, network slice ID, and radio access technology to facilitate secure data plane traffic in mobile networks without requiring security equipment in the service provider's core mobile networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security equipment is deployed in service provider's core mobile networks, then security enforcement capability is improved, but device complexity and deployment cost increase

Engineering Contradiction:
Improvesecurity enforcement capabilityVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a SASE solution as an intermediary system that sits between mobile devices and enterprise networks. This SASE solution includes a cloud-based security gateway that performs security enforcement functions, eliminating the need to deploy security equipment directly in the service provider's core network. The gateway uses contextual information from mobile networks to apply security policies, thereby maintaining security enforcement capability while avoiding the complexity of integrating security equipment into the core mobile network infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If context-based security is implemented, then security precision is improved, but information processing requirements increase

Engineering Contradiction:
Improvesecurity policy application precisionVSAvoidinformation processing resources
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent implements preliminary action by pre-establishing security policies and rules in the SASE solution before traffic needs to be secured. The system pre-processes and stores contextual information mappings (such as mapping mobile network identifiers to enterprise user identities) in advance. When traffic flows through the SASE gateway, the pre-configured policies and cached contextual information enable rapid security decisions without requiring intensive real-time processing, thus achieving precise context-based security while minimizing information processing resource consumption.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If seamless integration with mobile networks is achieved, then ease of operation is improved, but device complexity increases

Engineering Contradiction:
Improveintegration seamlessnessVSAvoidsystem architecture complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the security enforcement functions from the core mobile network infrastructure and places them in a separate SASE solution. This extraction allows the mobile network to continue operating with its existing architecture without modification, achieving seamless integration. The SASE solution independently handles security functions by receiving contextual information from mobile networks via standardized interfaces (such as PCRF or AAA interfaces) and applying security policies, thereby maintaining ease of operation while avoiding the complexity of modifying the core mobile network system.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20250323949A1Service access service edge solution for providing enhanced security for mobile networks
Publication Date: 2025.10.16 PALO ALTO NETWORKS INC
  • US20250323949A1 patent drawing
  • US20250323949A1 patent drawing
  • US20250323949A1 patent drawing

AI summary

Techniques for providing security for providing a Secure Access Service Edge (SASE) solution for enhanced security for mobile networks (e.g., service provider networks for mobile subscribers) are disclosed. In some embodiments, various techniques to apply per network slice security in mobile networks with SASE are disclosed. In some embodiments, various techniques to apply per subscriber identity and/or equipment identity and/or subscriber number security in mobile networks with SASE are disclosed. In some embodiments, various techniques to apply per access point name/data network name (APN/DNN) security in mobile networks with SASE are disclosed. In some embodiments, various techniques to apply per location security in mobile networks with SASE are disclosed. In some embodiments, various techniques to apply per Radio Access Technology (RAT) security in mobile networks with SASE are disclosed.