IP Library Granted Patent US 12665932
Granted Patent B2
US 12665932 · App. 18/608,509 · Granted Jun 23, 2026

Middlebox security in a wireless network

Inventors: Soo Bum Lee (San Diego, CA); Gavin Bernard Horn (La Jolla, CA)
Assignee: QUALCOMM Incorporated
H04L63/20H04W12/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12665932
App. No.
18/608,509
Granted
Jun 23, 2026
Kind
B2
Abstract

Various aspects of the present disclosure generally relate to wireless communication. In some aspects, a network entity may receive, from a security service device, a middlebox security policy, wherein the middlebox security policy is associated with a user equipment (UE) and a service device, and wherein the middlebox security policy indicates a set of authorization policies relating to one or more of the UE or the service device. The network entity may receive a communication on a communication link between the UE and the service device. The network entity may transmit the communication in accordance with the middlebox security policy. Numerous other aspects are described.

Claims (57)

1 . An apparatus for wireless communication at a service device, comprising:

one or more memories; and

one or more processors, coupled to the one or more memories, configured to cause the service device to:

initiate a service access for a connection with regard to a user equipment (UE);

transmit, to a security service device, a service key request;

receive, from the security service device, at least one of:

an authorization policy associated with a network entity,

an endpoint key associated with a security key for the network entity,

a root key from which the endpoint key is derivable, or

one or more middlebox key parameters;

receive a communication from the UE via the network entity, the communication having a protocol data unit (PDU) format that includes one or more mutable fields; and

verify, using the endpoint key, that a modification, an insertion, or a removal of the one or more mutable fields of the communication are authorized for the network entity in accordance with a middlebox security policy.

2 . The apparatus of claim 1 , wherein the one or more middlebox key parameters comprise one or more parameters from which a security key associated with the authorization policy or an authorized action can be derived.

3 . The apparatus of claim 1 , wherein the one or more processors are further configured to cause the service device to receive the middlebox security policy associated with the network entity.

4 . The apparatus of claim 1 , wherein the one or more processors, to cause the service device to receive the communication from the UE via the network entity, are configured to cause the service device to receive the communication in accordance with a tunneling protocol, wherein the network entity is configured as a proxy associated with the tunneling protocol.

5 . The apparatus of claim 1 , wherein the one or more processors are further configured to cause the service device to derive the endpoint key using the root key or the one or more middlebox key parameters.

6 . The apparatus of claim 1 , wherein the one or more processors configured to cause the service device to receive at least one of the authorization policy associated with the network entity, or the endpoint key, or the root key, or the one or more middlebox key parameters comprises the one or more processors configured to cause the service device to receive the authorization policy.

7 . The apparatus of claim 1 , wherein the one or more processors configured to cause the service device to receive at least one of the authorization policy associated with the network entity, or the endpoint key, or the root key, or the one or more middlebox key parameters comprises the one or more processors configured to cause the service device to receive the endpoint key.

8 . The apparatus of claim 1 , wherein the one or more processors configured to cause the service device to receive at least one of the authorization policy associated with the network entity, or the endpoint key, or the root key, or the one or more middlebox key parameters comprises the one or more processors configured to cause the service device to receive the root key.

9 . The apparatus of claim 1 , wherein the one or more processors configured to cause the service device to receive at least one of the authorization policy associated with the network entity, or the endpoint key, or the root key, or the one or more middlebox key parameters comprises the one or more processors configured to cause the service device to receive the one or more middlebox key parameters.

10 . A method of wireless communication at a service device, comprising:

initiating a service access for a connection with regard to a user equipment (UE);

transmitting, to a security service device, a service key request;

receiving, from the security service device, at least one of:

an authorization policy associated with a network entity,

an endpoint key associated with a security key for the network entity,

a root key from which the endpoint key is derivable, or

one or more middlebox key parameters;

receiving a communication from the UE via the network entity, the communication having a protocol data unit (PDU) format that includes one or more mutable fields; and

verifying, using the endpoint key, that a modification, an insertion, or a removal of the one or more mutable fields of the communication are authorized for the network entity in accordance with a middlebox security policy.

11 . The method of claim 10 , wherein the one or more middlebox key parameters comprise one or more parameters from which a security key associated with the authorization policy or an authorized action can be derived.

12 . The method of claim 10 , further comprising:

receiving the middlebox security policy associated with the network entity.

13 . The method of claim 10 , wherein receiving the communication from the UE via the network entity comprises:

receiving the communication in accordance with a tunneling protocol, wherein the network entity is configured as a proxy associated with the tunneling protocol.

14 . The method of claim 10 , further comprising:

deriving the endpoint key using the root key.

15 . The method of claim 10 , further comprising:

deriving the endpoint key using the one or more middlebox key parameters.

16 . A non-transitory computer-readable medium storing a set of instructions for wireless communication comprising:

one or more instructions that, when executed by one or more processors of a service device, cause the service device to:

initiate a service access for a connection with regard to a user equipment (UE);

transmit, to a security service device, a service key request;

receive, from the security service device, at least one of:

an authorization policy associated with a network entity,

an endpoint key associated with a security key for the network entity,

a root key from which the endpoint key is derivable, or

one or more middlebox key parameters;

receive a communication from the UE via the network entity, the communication having a protocol data unit (PDU) format that includes one or more mutable fields; and

verify, using the endpoint key, that a modification, an insertion, or a removal of the one or more mutable fields of the communication are authorized for the network entity in accordance with a middlebox security policy.

17 . The non-transitory computer-readable medium of claim 16 , wherein the one or more middlebox key parameters comprise one or more parameters from which a security key associated with the authorization policy or an authorized action can be derived.

18 . The non-transitory computer-readable medium of claim 16 , further comprising instructions that cause the service device to:

receive the middlebox security policy associated with the network entity.

19 . The non-transitory computer-readable medium of claim 16 , wherein the instructions that cause the service device to receive the communication from the UE via the network entity comprise instructions that cause the service device to:

receive the communication in accordance with a tunneling protocol, wherein the network entity is configured as a proxy associated with the tunneling protocol.

20 . The non-transitory computer-readable medium of claim 16 , further comprising instructions that cause the service device to:

derive the endpoint key using the root key or the one or more middlebox key parameters.