IP Library Granted Patent US 12689900
Granted Patent B2
US 12689900 · App. 18/320,352 · Granted Jul 21, 2026

User equipment vulnerability management based traffic routing with multi access edge compute

Inventors: Robert Edgar Barton (Richmond, CA); Flemming Stig Andreasen (Marlboro, NJ)
Assignee: CISCO TECHNOLOGY, INC.
H04W12/12H04W12/033H04W28/0215
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12689900
App. No.
18/320,352
Granted
Jul 21, 2026
Kind
B2
Abstract

A method to counter vulnerabilities associated with user equipment in operating via a 5G core architecture. The method includes monitoring a session between a user equipment and an endpoint, obtaining a vulnerability score for a vulnerability affecting the user equipment, selecting, based on the vulnerability score, a selected user plane function and a security service, accessible via the selected user plane function, to counter the vulnerability affecting the user equipment, and causing a packet flow of the session to be steered to the security service via the selected user plane function.

Claims (35)

1 . A method comprising:

monitoring a session, through a mobile core network that includes an application function, between a user equipment and an endpoint;

obtaining a vulnerability score for a vulnerability affecting the user equipment;

selecting, based on a combination of the vulnerability score and a protocol data unit session policy set by the application function, a selected user plane function and a security service, accessible via the selected user plane function, to counter the vulnerability affecting the user equipment, wherein the selected user plane function is part of the mobile core network; and

causing a packet flow of the session to be steered to the security service via the selected user plane function.

2 . The method of claim 1 , wherein the session is a session being processed by the mobile core network.

3 . The method of claim 2 , wherein the method is performed, at least in part, by a session management function of the mobile core network.

4 . The method of claim 1 , further comprising obtaining the vulnerability score from a Common Vulnerability Scoring System.

5 . The method of claim 1 , wherein the selected user plane function operates as an uplink classifier and branching point.

6 . The method of claim 1 , wherein the selected user plane function operates as a local protocol data unit session anchor.

7 . The method of claim 1 , wherein the selected user plane function is selected based on at least one of latency to reach the security service and bandwidth to reach the security service.

8 . The method of claim 1 , wherein the security service is hosted by the selected user plane function.

9 . The method of claim 1 , wherein the security service is hosted by an edge application server.

10 . The method of claim 1 , further comprising tunneling the packet flow of the session to the security service.

11 . A device comprising:

an interface configured to enable network communications;

a memory; and

one or more processors coupled to the interface and the memory, and configured to:

monitor a session, through a mobile core network that includes an application function, between a user equipment and an endpoint;

obtain a vulnerability score for a vulnerability affecting the user equipment;

select, based on a combination of the vulnerability score and a protocol data unit session policy set by the application function, a selected user plane function and a security service, accessible via the selected user plane function, to counter the vulnerability affecting the user equipment, wherein the selected user plane function is part of the mobile core network; and

cause a packet flow of the session to be steered to the security service via the selected user plane function.

12 . The device of claim 11 , wherein the session is a session being processed by the mobile core network.

13 . The device of claim 12 , wherein the device is a session management function of the mobile core network.

14 . The device of claim 11 , wherein the one or more processors are further configured to obtain the vulnerability score from a Common Vulnerability Scoring System.

15 . The device of claim 11 , wherein the selected user plane function operates as an uplink classifier and branching point.

16 . The device of claim 11 , wherein the selected user plane function operates as a local protocol data unit (PDU) session anchor.

17 . The device of claim 11 , wherein the selected user plane function is selected based on at least one of latency to reach the security service and bandwidth to reach the security service.

18 . One or more non-transitory computer readable storage media encoded with instructions that, when executed by a processor, cause the processor to:

monitor a session, through a mobile core network that includes an application function, between a user equipment and an endpoint;

obtain a vulnerability score for a vulnerability affecting the user equipment;

select, based on a combination of the vulnerability score and a protocol data unit session policy set by the application function, a selected user plane function and a security service, accessible via the selected user plane function, to counter the vulnerability affecting the user equipment, wherein the selected user plane function is part of the mobile core network; and

cause a packet flow of the session to be steered to the security service via the selected user plane function.

19 . The one or more non-transitory computer readable storage media of claim 18 , wherein the processor is part of a session management function of the mobile core network.

20 . The one or more non-transitory computer readable storage media of claim 18 , wherein the instructions, when executed by the processor, are configured to obtain the vulnerability score from a Common Vulnerability Scoring System.