Security Platform for Dynamic Policy Enforcement in Service Provider Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Service provider networks face challenges in implementing dynamic and location-based security policies for wireless devices, as they cannot currently define security policies on a per-endpoint or per-flow basis, nor can they utilize hardware attributes or location information for wireless devices communicating over their networks.
Innovation Solution
The implementation of a security platform that monitors GPRS Tunneling Protocol (GTP) communications, including GTP-C and GTP-U messages, to extract parameters such as IMEI, IMSI, location, and RAT, allowing for the application of granular security policies based on these parameters using next-generation firewalls.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional firewalls are used to protect service provider networks, then basic network security is provided, but dynamic and location-based security policies cannot be implemented and security cannot be enforced on a per-endpoint or per-flow basis
Solution Approach 1:
The patent implements dynamic security policies that can change based on real-time conditions such as device location, endpoint identity, and flow characteristics. The system continuously monitors network traffic and automatically adjusts security rules without requiring manual reconfiguration, allowing security policies to adapt to changing network conditions and threats.
Solution Approach 2:
The patent segments security enforcement into granular per-endpoint and per-flow policies rather than applying blanket security rules to entire networks. By identifying individual devices and traffic flows, the system can apply customized security measures to each segment, enabling location-based and application-specific security controls.
2Reliability
If granular security policies are implemented per subscriber and device, then network security and flexibility are improved, but system complexity increases
Solution Approach 1:
The patent creates a universal security platform that handles multiple security functions through a single system. The platform simultaneously performs traffic monitoring, policy enforcement, location tracking, and dynamic rule generation, eliminating the need for multiple separate security systems and reducing overall complexity despite the granular nature of security policies.
Data Source
AI summary
Techniques for access point name and application identity based security enforcement in service provider networks (e.g., service provider networks for mobile subscribers) are disclosed. In some embodiments, a system/process/computer program product for access point name (e.g., APN) and application identity (e.g., application identifier) based security enforcement in service provider networks includes monitoring network traffic on a service provider network at a security platform to identify an access point name for a new session; determining an application identifier for user traffic associated with the new session at the security platform; and determining a security policy to apply at the security platform to the new session based on the access point name and the application identifier.


