Security Platform for Dynamic Subscriber Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Service provider networks face challenges in implementing dynamic security policies on a per-subscriber and per-flow basis, requiring network infrastructure updates and lacking real-time granular control, which hinders flexible and secure communication management.
Innovation Solution
Implementing a security platform that uses passive and active monitoring techniques, along with communication with network elements like PCRF, AAA, and LDAP servers, to dynamically apply and enforce security policies based on subscriber-type, IP address, and access point names, enabling real-time granular security policy management across 3GPP and non-3GPP interfaces.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional firewall rules are used for network security, then basic access control is provided, but real-time dynamic security policy enforcement per subscriber and IP flow cannot be achieved
Solution Approach 1:
The patent introduces a security platform as an intermediary component that sits between the network elements and subscribers. This platform receives security policy decisions from network elements (PCRF, AAA, LDAP servers) and enforces them dynamically across multiple subscribers and flows. The intermediary handles the complexity of real-time policy management, allowing traditional firewalls to remain relatively simple while achieving advanced security capabilities through the added security platform layer.
Solution Approach 2:
The security platform performs multiple functions including receiving policy decisions from various network elements (PCRF, AAA, LDAP), storing security policies, determining applicable policies for different subscribers and flows, and enforcing those policies. This multi-functional approach consolidates what would otherwise require multiple separate systems, reducing overall infrastructure complexity while providing comprehensive dynamic security control.
2Ease of operation
If static security policies are implemented, then network infrastructure remains stable, but real-time granular security control per subscriber and flow cannot be provided
Solution Approach 1:
The system transitions from static firewall rules to dynamic security policies that are determined in real-time based on subscriber identity, IP flow characteristics, and network element decisions. The security platform dynamically selects and enforces appropriate policies for each subscriber and flow combination, allowing the network to adapt to changing security requirements while maintaining operational stability through automated policy management.
Solution Approach 2:
The security platform implements feedback mechanisms by continuously monitoring network traffic, subscriber information, and policy decisions from network elements. Based on this feedback, the platform adjusts security policy enforcement in real-time, ensuring that the most appropriate security measures are applied to each subscriber and flow while maintaining overall network stability through automated adjustments rather than manual interventions.
3Measurement precision
If comprehensive security monitoring is implemented, then security coverage is improved, but processing time and system resource consumption increase
Solution Approach 1:
The security platform performs preliminary actions by pre-receiving and storing security policy decisions from network elements (PCRF, AAA, LDAP servers) before they are needed for enforcement. This advance preparation allows the platform to quickly retrieve and apply appropriate policies when security decisions are required, reducing processing time while maintaining comprehensive security coverage. The policies are prepared in advance based on subscriber authentication and network element decisions.
Data Source
AI summary
Techniques for providing a securing platform for service provider network environments are disclosed. In some embodiments, a system/process/computer program product for providing a securing platform for service provider network environments includes communicating with an orchestrator and/or another network element on a service provider network to identify a subscriber with a new IP flow using a security platform; associating the subscriber with the new IP flow at the security platform; and determining a security policy to apply at the security platform to the new IP flow based on the subscriber.


