Security Platform for Dynamic Subscriber Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Service provider networks face challenges in implementing dynamic security policies on a per-subscriber and per-flow basis, requiring network infrastructure updates and lacking real-time granular control, which hinders flexible and secure communication management.

Innovation Solution

Implementing a security platform that uses passive and active monitoring techniques, along with communication with network elements like PCRF, AAA, and LDAP servers, to dynamically apply and enforce security policies based on subscriber-type, IP address, and access point names, enabling real-time granular security policy management across 3GPP and non-3GPP interfaces.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional firewall rules are used for network security, then basic access control is provided, but real-time dynamic security policy enforcement per subscriber and IP flow cannot be achieved

Engineering Contradiction:
Improvesecurity policy flexibilityVSAvoidnetwork infrastructure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a security platform as an intermediary component that sits between the network elements and subscribers. This platform receives security policy decisions from network elements (PCRF, AAA, LDAP servers) and enforces them dynamically across multiple subscribers and flows. The intermediary handles the complexity of real-time policy management, allowing traditional firewalls to remain relatively simple while achieving advanced security capabilities through the added security platform layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security platform performs multiple functions including receiving policy decisions from various network elements (PCRF, AAA, LDAP), storing security policies, determining applicable policies for different subscribers and flows, and enforcing those policies. This multi-functional approach consolidates what would otherwise require multiple separate systems, reducing overall infrastructure complexity while providing comprehensive dynamic security control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If static security policies are implemented, then network infrastructure remains stable, but real-time granular security control per subscriber and flow cannot be provided

Engineering Contradiction:
Improvesecurity policy managementVSAvoidnetwork stability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system transitions from static firewall rules to dynamic security policies that are determined in real-time based on subscriber identity, IP flow characteristics, and network element decisions. The security platform dynamically selects and enforces appropriate policies for each subscriber and flow combination, allowing the network to adapt to changing security requirements while maintaining operational stability through automated policy management.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The security platform implements feedback mechanisms by continuously monitoring network traffic, subscriber information, and policy decisions from network elements. Based on this feedback, the platform adjusts security policy enforcement in real-time, ensuring that the most appropriate security measures are applied to each subscriber and flow while maintaining overall network stability through automated adjustments rather than manual interventions.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If comprehensive security monitoring is implemented, then security coverage is improved, but processing time and system resource consumption increase

Engineering Contradiction:
Improvesecurity policy enforcement accuracyVSAvoidpolicy determination time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The security platform performs preliminary actions by pre-receiving and storing security policy decisions from network elements (PCRF, AAA, LDAP servers) before they are needed for enforcement. This advance preparation allows the platform to quickly retrieve and apply appropriate policies when security decisions are required, reducing processing time while maintaining comprehensive security coverage. The policies are prepared in advance based on subscriber authentication and network element decisions.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12120092B2Security platform for service provider network environments
Publication Date: 2024.10.15 PALO ALTO NETWORKS INC
  • US12120092B2 patent drawing
  • US12120092B2 patent drawing
  • US12120092B2 patent drawing

AI summary

Techniques for providing a securing platform for service provider network environments are disclosed. In some embodiments, a system/process/computer program product for providing a securing platform for service provider network environments includes communicating with an orchestrator and/or another network element on a service provider network to identify a subscriber with a new IP flow using a security platform; associating the subscriber with the new IP flow at the security platform; and determining a security policy to apply at the security platform to the new IP flow based on the subscriber.