Zero-Trust Workload Access via 5G MEC Security Steering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

5G networks face security challenges as they are designed to secure network traffic but not the workloads running on top of them, and existing cloud-based security solutions do not effectively manage data traffic between User Equipment (UE) and Multiaccess Edge Compute (MEC) devices, leading to increased security risks due to unsecured and unmanaged devices.

Innovation Solution

Integrate cloud-based security services within service provider's MECs, enabling intelligent steering of traffic types to the most effective edge for processing, securing, and logging, while ensuring workload isolation through dynamic, unique, and encrypted tunnels, independent of underlying mobile network transports.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cloud-based security services are integrated within service provider's MECs, then security coverage for workloads is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges cloud-based security services with MEC infrastructure by integrating security functions into edge compute nodes. This consolidation allows security services to be delivered closer to users without requiring separate dedicated security appliances, thereby improving security coverage while managing system complexity through functional integration.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The MEC infrastructure is designed to provide multiple functions including compute, storage, networking, and security services. By making the MEC platform universal and multi-functional, the system can deliver comprehensive security coverage without proportionally increasing complexity, as the same infrastructure handles both workloads and security functions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If intelligent steering of traffic types to the most effective edge is implemented, then network performance is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork performanceVSAvoidsteering complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system implements dynamic traffic steering that adapts to real-time network conditions, user location, and workload requirements. Traffic routing decisions are made dynamically based on current network state rather than static configurations, improving network performance while the automation reduces operational complexity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The intelligent steering mechanism incorporates feedback loops that continuously monitor network performance metrics and adjust traffic routing accordingly. This feedback-driven approach optimizes network performance automatically, reducing the need for manual intervention and simplifying operations.

Inventive Principle:
Principle #23Feedback

3Reliability

If workload isolation through dynamic encrypted tunnels is ensured, then security is improved, but device complexity increases

Engineering Contradiction:
Improveworkload isolationVSAvoidisolation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments network traffic into isolated logical channels using dynamic encrypted tunnels for different workloads and users. This segmentation ensures that workloads are isolated from each other at the network level, improving security while the tunneling mechanism provides a standardized approach to isolation that manages complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Encrypted tunnels act as intermediaries between workloads and the network infrastructure. These tunnels provide a standardized interface that handles security isolation automatically, allowing workloads to communicate securely without needing to implement complex isolation mechanisms themselves, thus improving security while managing complexity at the infrastructure level.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12389223B2Zero-trust enabled workload access for user equipment
Publication Date: 2025.08.12 ZSCALER INC
  • US12389223B2 patent drawing
  • US12389223B2 patent drawing
  • US12389223B2 patent drawing

AI summary

The present disclosure relates to systems and methods for cloud-based 5G security network architectures intelligent steering, workload isolation, identity, and secure edge steering. Specifically, various approaches are described to integrate cloud-based security services into Multiaccess Edge Compute servers (MECs). That is, existing cloud-based security services are in line between a UE and the Internet. The present disclosure includes integrating the cloud-based security services and associated cloud-based system within service provider's MECs. In this manner, a cloud-based security service can be integrated with a service provider's 5G network or a 5G network privately operated by the customer. For example, nodes in a cloud-based system can be collocated within a service provider's network, to provide security functions to 5G users or connected by peering from the cloud-based security service into the 5G service provider's regional communications centers.