5G Security Platform S-NSSAI DNN Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Service providers in mobile networks face challenges in implementing dynamic and endpoint-specific security policies, requiring new techniques for monitoring network traffic and applying security measures across wireless devices communicating over their networks.

Innovation Solution

The implementation of network slice-based security platforms that parse HTTP/2 messages to extract relevant information, such as S-NSSAI, SUPI, PEI, GPSI, and User Location, to apply customized security policies per endpoint or flow, enhancing threat detection and prevention in 5G cellular networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional firewall policies are used in mobile networks, then basic network security is provided, but dynamic and endpoint-specific security policies cannot be implemented

Engineering Contradiction:
Improvesecurity policy customizationVSAvoidsecurity platform complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments security policies by network slice (S-NSSAI) and data network name (DNN), allowing different security rules to be applied to different network slices and endpoints. This enables customized security policies for different subscribers and devices while maintaining a structured management framework that prevents excessive complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces new dimensions for security policy differentiation by incorporating network slice identifier (S-NSSAI) and data network name (DNN) as additional policy parameters. This multi-dimensional approach allows security policies to be customized across multiple axes (slice, network, endpoint) without linearly increasing system complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If network traffic monitoring is implemented to apply security policies, then threat detection capability is improved, but network performance and latency are degraded

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidnetwork throughput
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent applies partial inspection by monitoring only the HTTP/2 control plane messages (HEADERS and DATA frames) that contain S-NSSAI and DNN information, rather than inspecting the entire user plane traffic. This selective monitoring approach enables threat detection based on network slice and data network context while minimizing the performance overhead of deep packet inspection.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The security platform extracts and processes security-relevant information (S-NSSAI, DNN) from HTTP/2 messages in advance, before user data traffic needs to be inspected. This preliminary extraction creates a cache of security context that can be quickly referenced during threat detection, reducing real-time processing requirements and network latency.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If HTTP/2 message parsing is used to extract security information, then endpoint-specific security policies are enabled, but processing overhead and complexity increase

Engineering Contradiction:
Improveendpoint identification capabilityVSAvoidmessage parsing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts only the specific fields needed for security policy enforcement (S-NSSAI from the :path or :authority header, and DNN from the payload) from HTTP/2 messages, rather than parsing and analyzing the entire message structure. This selective extraction reduces processing complexity while maintaining the ability to identify endpoints and apply appropriate security policies.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If comprehensive security services are provided per network slice, then network security and resilience are improved, but system resource consumption increases

Engineering Contradiction:
Improvenetwork securityVSAvoidprocessing energy
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies security services locally to each network slice and data network combination, rather than uniformly across the entire network. By processing and enforcing security policies only where needed (per S-NSSAI and DNN), the system provides comprehensive security coverage while minimizing energy consumption in network segments that do not require intensive security processing.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10812971B2Service-based security per data network name in mobile networks
Publication Date: 2020.10.20 PALO ALTO NETWORKS INC
  • US10812971B2 patent drawing
  • US10812971B2 patent drawing
  • US10812971B2 patent drawing

AI summary

Techniques for providing service-based security per data network name in mobile networks (e.g., service provider networks for mobile subscribers) are disclosed. In some embodiments, a system/process/computer program product for service-based security per data network name in mobile networks in accordance with some embodiments includes monitoring network traffic on a service provider network at a security platform to identify a new session, wherein the service provider network includes a 5G network or a converged 5G network; extracting network name information for user traffic associated with the new session at the security platform; and determining a security policy to apply at the security platform to the new session based on the network name information.