IP Library Granted Patent US 12706954
Granted Patent B2
US 12706954 · App. 18/439,415 · Granted Aug 11, 2026

Enabling device context awareness, data ingestion and real-time actions in mobile networks

Inventors: Mitchell Rappard (Lee's Summit, MO); Justin Tyler Rorabaugh (Pflugerville, TX); Lior Kolnik (Leander, TX); John Plant (Cedar Park, TX); Leonid Burakovsky (Pleasanton, CA); Sachin Verma (Danville, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/20H04L61/503
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12706954
App. No.
18/439,415
Granted
Aug 11, 2026
Kind
B2
Abstract

Techniques for data ingestion enabling context awareness and real-time actions in mobile networks are disclosed. In some embodiments, a system, a process, and/or a computer program product for data ingestion enabling context awareness and real-time actions in mobile networks includes extracting a plurality of parameters from a mobile core network entity using an application programming interface (API) call, messages over a message broker, and/or logs from the mobile core network entity; determining a context for a session using one or more of the plurality of parameters associated with a mobile device communicating over the mobile core network; and applying a security policy using a security platform to the session based on the context.

Claims (34)

1 . A system, comprising:

a processor configured to:

extract a plurality of parameters from a mobile core network entity using an application programming interface (API) call, messages over a message broker, and/or logs from the mobile core network entity, wherein the plurality of parameters includes two or four or more of the following: Integrated Circuit Card Identifier (ICCID), Radio Access Technology (RAT), Access Point Name (APN), Quality of Service (QoS) parameters, Public Land Mobile Network Identifier (PLMNID), radio ID Next Generation Node B identifier (gNodeB ID), User Equipment (UE) State Connected, UE State Disconnected, and/or UE State Idle;

determine a context for a session using one or more of the plurality of parameters associated with a mobile device communicating over the mobile core network; and

apply a security policy using a security platform to the session based on the context; and

a memory coupled to the processor and configured to provide the processor with instructions.

2 . The system of claim 1 , wherein the mobile core network is a 5G mobile core network.

3 . The system of claim 1 , wherein the mobile core network is a 4G mobile core network.

4 . The system of claim 1 , wherein the mobile core network is a 4G/5G mobile core network.

5 . The system of claim 1 , wherein the mobile core network is a private 4G/5G mobile core network.

6 . The system of claim 1 , wherein the plurality of parameters from the mobile core network are extracted using the API call and sent over a RADIUS protocol.

7 . The system of claim 1 , wherein the plurality of parameters from the mobile core network are extracted using the API call and sent over a RADIUS protocol in communication with the security platform.

8 . The system of claim 1 , wherein the plurality of parameters from the mobile core network are extracted using the API call and sent over a RADIUS protocol and using an XSOAR entity in communication with a 4G/5G Orchestration API entity.

9 . The system of claim 1 , wherein the plurality of parameters from the mobile core network are extracted using the API call and sent over a RADIUS protocol and using an XSOAR entity in communication with a 4G/5G Orchestration API entity using a push and/or a pull protocol.

10 . The system of claim 1 , wherein the plurality of parameters from the mobile core network are extracted using the API call and sent over a RADIUS protocol and using a centralized XSOAR entity in communication with a 4G/5G Orchestration API entity.

11 . The system of claim 1 , wherein the plurality of parameters from the mobile core network are extracted using the API call and sent over a RADIUS protocol and using a distributed XSOAR entity in communication with a 4G/5G Orchestration API entity.

12 . The system of claim 1 , wherein the plurality of parameters from the mobile core network are extracted using the API call and sent over a RADIUS protocol and using a multi-tenant XSOAR entity for a managed security service provider (MSSP) in communication with a 4G/5G Orchestration API entity.

13 . The system of claim 1 , wherein the processor is further configured to:

enrich one or more of the plurality of parameters via another API call to a third-party service that provides additional meta information for the one or more of the plurality of parameters.

14 . The system of claim 1 , wherein the processor is further configured to:

enrich log data and/or security alert data with context based on the one or more of the plurality of parameters.

15 . A method, comprising:

extracting a plurality of parameters from a mobile core network entity using an application programming interface (API) call, messages over a message broker, and/or logs from the mobile core network entity, wherein the plurality of parameters includes two or four or more of the following: Integrated Circuit Card Identifier (ICCID), Radio Access Technology (RAT), Access Point Name (APN), Quality of Service (QoS) parameters, Public Land Mobile Network Identifier (PLMNID), radio ID Next Generation Node B identifier (gNodeB ID), User Equipment (UE) State Connected, UE State Disconnected, and/or UE State Idle;

determining a context for a session using one or more of the plurality of parameters associated with a mobile device communicating over the mobile core network; and

applying a security policy using a security platform to the session based on the context.

16 . The method of claim 15 , wherein the plurality of parameters from the mobile core network are extracted using the API call and sent over a RADIUS protocol.

17 . The method of claim 15 , wherein the plurality of parameters from the mobile core network are extracted using the API call and sent over a RADIUS protocol in communication with the security platform.

18 . A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:

extracting a plurality of parameters from a mobile core network entity using an application programming interface (API) call, messages over a message broker, and/or logs from the mobile core network entity, wherein the plurality of parameters includes two or four or more of the following: Integrated Circuit Card Identifier (ICCID), Radio Access Technology (RAT), Access Point Name (APN), Quality of Service (QoS) parameters, Public Land Mobile Network Identifier (PLMNID), radio ID Next Generation Node B identifier (gNodeB ID), User Equipment (UE) State Connected, UE State Disconnected, and/or UE State Idle;

determining a context for a session using one or more of the plurality of parameters associated with a mobile device communicating over the mobile core network; and

applying a security policy using a security platform to the session based on the context.

19 . The computer program product of claim 18 , wherein the plurality of parameters from the mobile core network are extracted using the API call and sent over a RADIUS protocol.

20 . The computer program product of claim 18 , wherein the plurality of parameters from the mobile core network are extracted using the API call and sent over a RADIUS protocol in communication with the security platform.

21 . The system of claim 1 , wherein the plurality of parameters includes the following: Integrated Circuit Card Identifier (ICCID), Radio Access Technology (RAT), Access Point Name (APN), Quality of Service (QoS) parameters, Public Land Mobile Network Identifier (PLMNID), radio ID Next Generation Node B identifier (gNodeB ID), User Equipment (UE) State Connected, UE State Disconnected, and UE State Idle.