Security Platform for Dynamic IoT Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Service provider networks face challenges in implementing dynamic and location-based security policies for wireless devices, as they cannot currently define security policies per endpoint or flow, nor based on device attributes like IMEI or location, requiring new techniques for monitoring and enforcing security policies.

Innovation Solution

Implementing a security platform that monitors GTP communications and applies policies based on parameters like IMEI, IMSI, location, and Radio Access Technology (RAT) using next-generation firewalls, enabling real-time, granular security enforcement for mobile and IoT devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional firewalls are used to protect networks, then basic network security is provided, but dynamic and location-based security policies cannot be implemented and policies cannot be defined per endpoint or flow

Engineering Contradiction:
Improvesecurity policy adaptabilityVSAvoidsecurity platform complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments security policies into multiple dimensions including device identity (IMEI, IMSI), location information, application identity, and flow characteristics. This allows independent configuration and enforcement of granular security rules for different endpoints and traffic flows, transforming traditional monolithic firewall policies into modular, context-aware security rules that can be dynamically applied without requiring complete system redesign

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic security policies that adapt in real-time based on device identity, location, application behavior, and network conditions. The security platform continuously monitors these parameters and automatically adjusts policy enforcement, enabling security rules to evolve with changing network conditions and threat landscapes without manual intervention for each scenario

Inventive Principle:
Principle #15Dynamics

2Measurement precision

If granular security policies per subscriber and device are implemented, then security precision is improved, but monitoring and enforcement complexity increases

Engineering Contradiction:
Improvesecurity policy precisionVSAvoidpolicy monitoring difficulty
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a security platform as an intermediary component that sits between the network core and endpoints. This platform consolidates the complexity of monitoring device identities, locations, and application behaviors in one centralized location, while presenting simplified policy enforcement interfaces to network elements. The intermediary handles the heavy lifting of granular policy evaluation and decision-making, reducing the monitoring burden on individual network components

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security platform performs multiple functions simultaneously: it monitors device identities, tracks location information, analyzes application behavior, enforces security policies, and generates security events. This multi-functional approach consolidates what would otherwise require separate monitoring systems for each parameter, reducing overall system complexity while maintaining high policy precision through integrated multi-dimensional analysis

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If real-time security enforcement based on multiple parameters is applied, then threat detection capability is improved, but processing time and system resource usage increase

Engineering Contradiction:
Improvethreat detection reliabilityVSAvoidpolicy enforcement time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-configuring security policies with defined criteria and enforcement rules before network traffic arrives. Device identities, location parameters, and application profiles are pre-registered and associated with security rules in advance. When traffic flows through the network, the security platform performs rapid pattern matching against these pre-configured rules rather than analyzing each packet from scratch, dramatically reducing real-time processing requirements while maintaining comprehensive threat detection

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11838326B2Mobile equipment identity and/or IoT equipment identity and application identity based security enforcement in service provider networks
Publication Date: 2023.12.05 PALO ALTO NETWORKS INC
  • US11838326B2 patent drawing
  • US11838326B2 patent drawing
  • US11838326B2 patent drawing

AI summary

Techniques for mobile equipment identity and/or IoT equipment identity and application identity based security enforcement in service provider networks (e.g., service provider networks for mobile subscribers) are disclosed. In some embodiments, a system/process/computer program product for mobile equipment identity and/or IoT equipment identity and application identity based security enforcement in service provider networks includes monitoring network traffic on a service provider network at a security platform to identify a device identifier for a new session; determining an application identifier for user traffic associated with the new session at the security platform; and determining a security policy to apply at the security platform to the new session based on the device identifier and the application identifier.