Security Platform for Dynamic Policy Enforcement in Service Provider Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Service provider networks face challenges in implementing dynamic and location-based security policies for wireless devices, as they cannot currently define security policies on a per-endpoint or per-flow basis, nor can they utilize hardware attributes or location information for wireless devices communicating over their networks.

Innovation Solution

The implementation of a security platform that monitors GPRS Tunneling Protocol (GTP) communications, including GTP-C and GTP-U messages, to extract parameters such as IMEI, IMSI, location, and RAT, allowing for the application of granular security policies based on these parameters using next-generation firewalls.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional firewalls are used to protect service provider networks, then basic network security is provided, but dynamic and location-based security policies cannot be implemented and security cannot be enforced on a per-endpoint or per-flow basis

Engineering Contradiction:
Improvesecurity policy flexibilityVSAvoidnetwork security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements dynamic security policies that can change based on real-time conditions such as device location, endpoint identity, and flow characteristics. The system continuously monitors network traffic and automatically adjusts security rules without requiring manual reconfiguration, allowing security policies to adapt to changing network conditions and threats.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent segments security enforcement into granular per-endpoint and per-flow policies rather than applying blanket security rules to entire networks. By identifying individual devices and traffic flows, the system can apply customized security measures to each segment, enabling location-based and application-specific security controls.

Inventive Principle:
Principle #1Segmentation

2Reliability

If granular security policies are implemented per subscriber and device, then network security and flexibility are improved, but system complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsecurity platform complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal security platform that handles multiple security functions through a single system. The platform simultaneously performs traffic monitoring, policy enforcement, location tracking, and dynamic rule generation, eliminating the need for multiple separate security systems and reducing overall complexity despite the granular nature of security policies.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12010148B2Access point name and application identity based security enforcement in service provider networks
Publication Date: 2024.06.11 PALO ALTO NETWORKS INC
  • US12010148B2 patent drawing
  • US12010148B2 patent drawing
  • US12010148B2 patent drawing

AI summary

Techniques for access point name and application identity based security enforcement in service provider networks (e.g., service provider networks for mobile subscribers) are disclosed. In some embodiments, a system/process/computer program product for access point name (e.g., APN) and application identity (e.g., application identifier) based security enforcement in service provider networks includes monitoring network traffic on a service provider network at a security platform to identify an access point name for a new session; determining an application identifier for user traffic associated with the new session at the security platform; and determining a security policy to apply at the security platform to the new session based on the access point name and the application identifier.