Smart NIC Selective Enforcement for Mobile Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security solutions for mobile networks lack efficient and cost-effective methods for selective intelligent enforcement and offloading, leading to increased network traffic and higher security analysis costs.

Innovation Solution

Implementing a security platform that uses a Smart NIC to monitor network traffic, extract meta information, and apply selective intelligent enforcement or offloading based on policies related to network slice information, subscriber/equipment identity, access point name/data network name, location, and radio access technology.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security enforcement is applied to all network traffic, then network security is improved, but network traffic load and security analysis costs increase

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork traffic load
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent segments network traffic into different categories based on policy criteria (network slice information, subscriber identity, equipment identity, location, etc.). Only specific traffic segments that match enforcement policies undergo security analysis, while other segments are offloaded. This selective segmentation resolves the contradiction by maintaining security for critical traffic while reducing overall traffic load on security platforms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security enforcement qualities to different parts of the network traffic based on local characteristics. High-priority traffic (e.g., from specific network slices, locations, or subscribers) receives full security enforcement, while low-priority traffic receives minimal or no enforcement. This local differentiation maintains security where needed while reducing overall traffic load and costs.

Inventive Principle:
Principle #3Local quality

2Measurement precision

If comprehensive security analysis is performed on all traffic, then security detection capability is improved, but processing time and resource consumption increase

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies partial security analysis only to the extent necessary for specific traffic types. Instead of performing comprehensive security analysis on all traffic, the system applies enforcement selectively based on policy matches. This partial action maintains adequate security detection capability for critical traffic while significantly reducing processing time and resource consumption for the overall network.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If security enforcement is applied uniformly across all network slices and subscribers, then security coverage is improved, but system complexity and cost increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments security enforcement into multiple policy levels corresponding to different network slices, subscribers, equipment, and locations. Each segment has its own enforcement rules, allowing the system to manage complexity through organized segmentation while maintaining comprehensive security coverage across all segments through centralized policy management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal security platform that handles multiple functions through a single system. The security enforcement mechanism works across all network slices, subscribers, and traffic types by applying different policies from a unified framework. This multi-functional approach improves security coverage while avoiding the complexity of separate security systems for each traffic type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250031048A1Selective intelligent enforcement and/or selective offloading for mobile networks using a smart network interface card
Publication Date: 2025.01.23 PALO ALTO NETWORKS INC
  • US20250031048A1 patent drawing
  • US20250031048A1 patent drawing
  • US20250031048A1 patent drawing

AI summary

Techniques for selective intelligent enforcement and/or selective intelligent offloading for mobile networks using a smart network interface card are disclosed. In some embodiments, a system/process/computer program product for selective intelligent enforcement and/or selective intelligent offloading for mobile networks using a smart network interface card includes monitoring network traffic in a core mobile network using a Smart Network Interface Card (NIC) of a network element in the core mobile network to identify a new session that attached to the core mobile network for mobile network communications; extracting meta information associated with the new session using the Smart NIC of the network element in the core mobile network; and applying selective intelligent enforcement and/or selective intelligent offloading using the Smart NIC of the network element if the extracted meta information associated with the new session matches a selective intelligent enforcement policy and/or a selective intelligent offload policy.