IP Library Granted Patent US 8,423,760
Granted Patent B2
US 8,423,760 · App. 12/711,140 · Granted Apr 16, 2013

Method and system for reducing packet overhead for an LTE architecture while securing traffic in an unsecured environment

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,423,760
App. No.
12/711,140
Granted
Apr 16, 2013
Kind
B2
Abstract

A first packet is received at a network element from an E-UTRAN Node B (eNB) of an E-UTRAN access network via a secured communications tunnel of a secured connection, where the first packet encapsulates a second packet therein. It is determined whether the network element serves both a security gateway functionality and a serving gateway functionality of a core packet network based on the first packet and the second packet. The network element negotiates with the eNB to switch further communications from a tunnel mode to a transport mode of the secured connection if it is determined that the network element serves both the security gateway functionality and the serving gateway functionality. Thereafter, the network element exchanges further packets with the eNB via the transport mode of the secured connection after the eNB switches from the tunnel mode to the transport mode.

Claims (44)

1. A machine-implemented method for optimizing packet process overhead while securing traffic in a packet network performed within a network element, the method comprising:

receiving, at a network element, a first packet from an evolved universal mobile telecommunications system (UMTS) terrestrial radio access network (RAN) (E-UTRAN) Node B (eNB) of an E-UTRAN access network via a secured communications tunnel of a secured connection, the first packet encapsulating a second packet therein;

determining at the network element whether the network element serves both a security gateway functionality and a serving gateway functionality of a core packet network based on the first packet and the second packet;

negotiating with the eNB to switch further communications from a tunnel mode to a transport mode of the secured connection if a determination is made that the network element serves both the security gateway functionality and the serving gateway functionality; and

exchanging further packets with the eNB via the transport mode of the secured connection after the eNB switches from the tunnel mode to the transport mode.

2. The method of claim 1 , wherein during the tunnel mode, the second packet is entirely encapsulated within the first packet using an Internet protocol security (IPsec) compatible encapsulating security payload (ESP) method.

3. The method of claim 2 , further comprising:

performing a corresponding ESP method to decrypt the first packet to reveal the second packet from the first packet;

comparing a first destination IP address of a first IP header of the first packet with a second destination IP address of a second IP header of the second packet; and

signaling that the network element serves both a security gateway functionality and a serving gateway functionality if the first destination IP address and the second destination IP address are identical.

4. The method of claim 3 , wherein the first destination IP address is associated with the network element, and wherein the second destination IP address is associated with the network element or a serving gateway of the core packet network.

5. The method of claim 3 , wherein exchanging further packets with the eNB comprises receiving a third packet from the eNB via an IPsec transport mode, wherein the third packet includes a third IP header identical to the second IP header without encapsulating another IP header therein.

6. The method of claim 3 , further comprising:

performing a general packet radio service (GPRS) tunnel protocol (GTP) process on a payload of the second packet; and

transmitting a result of the GTP process to a packet data network (PDN) gateway of the core packet network.

7. The method of claim 1 , wherein the network element is located at an edge of the core packet network interfacing one or more eNBs with the core packet network.

8. A network element, comprising:

a processor; and

a memory coupled to the processor storing instructions, which when executed from the memory, cause the processor to execute in the memory:

a security unit to receive a first packet from an evolved universal mobile telecommunications system (UMTS) terrestrial radio access network (RAN) (E-UTRAN) Node B (eNB) of an E-UTRAN access network via a secured communications tunnel of a secured connection, the first packet encapsulating a second packet therein;

a packet analyzer coupled to the security unit to determine at the network element whether the network element serves both a security gateway functionality and a serving gateway functionality of a core packet network based on the first packet and the second packet; and

a routing logic coupled to the security unit and the packet analyzer to negotiate with the eNB to switch further communications from a tunnel mode to a transport mode of the secured connection if it is determined that the network element serves both the security gateway functionality and the serving gateway functionality, wherein the routing logic exchanges further packets with the eNB via the transport mode of the secured connection after the eNB switches from the tunnel mode to the transport mode.

9. The network element of claim 8 , wherein during the tunnel mode, the second packet is entirely encapsulated within the first packet using an Internet protocol security (IPsec) compatible encapsulating security payload (ESP) method.

10. The network element of claim 9 , wherein the processor further executes in the memory a security unit to perform a corresponding ESP method to decrypt the first packet to reveal the second packet from the first packet, wherein the packet analyzer compares a first destination IP address of a first IP header of the first packet with a second destination IP address of a second IP header of the second packet, and wherein the packet analyzer indicates that the network element serves both a security gateway functionality and a serving gateway functionality if the first destination IP address and the second destination IP address are identical.

11. The network element of claim 10 , wherein the first destination IP address is associated with the network element, and wherein the second destination IP address is associated with the network element or a serving gateway of the core packet network.

12. The network element of claim 10 , wherein exchanging further packets with the eNB comprises receiving a third packet from the eNB via an IPsec transport mode, wherein the third packet includes a third IP header identical to the second IP header without encapsulating another IP header therein.

13. The network element of claim 10 , wherein the processor further executes in the memory a GTP unit to perform a general packet radio service (GPRS) tunnel protocol (GTP) process on a payload of the second packet and to transmit a result of the GTP process to a packet data network (PDN) gateway of the core packet network.

14. The network element of claim 8 , wherein the network element is located at an edge of the core packet network interfacing one or more eNBs with the core packet network.

15. A non-transitory machine-readable storage medium having instructions stored therein, which when executed by a machine, cause a machine to perform a method for optimizing packet process overhead while securing traffic in a packet network performed within a network element, the method comprising:

receiving, at a network element, a first packet from an evolved universal mobile telecommunications system (UMTS) terrestrial radio access network (RAN) (E-UTRAN) Node B (eNB) of an E-UTRAN access network via a secured communications tunnel of a secured connection, the first packet encapsulating a second packet therein;

determining at the network element whether the network element serves both a security gateway functionality and a serving gateway functionality of a core packet network based on the first packet and the second packet;

negotiating with the eNB to switch further communications from a tunnel mode to a transport mode of the secured connection if it is determined that the network element serves both the security gateway functionality and the serving gateway functionality; and

exchanging further packets with the eNB via the transport mode of the secured connection after the eNB switches from the tunnel mode to the transport mode.

16. The non-transitory machine-readable storage medium of claim 15 , wherein during the tunnel mode, the second packet is entirely encapsulated within the first packet using an Internet protocol security (IPsec) compatible encapsulating security payload (ESP) method.

17. The non-transitory machine-readable storage medium of claim 16 , wherein the method further comprises:

performing a corresponding ESP method to decrypt the first packet to reveal the second packet from the first packet;

comparing a first destination IP address of a first IP header of the first packet with a second destination IP address of a second IP header of the second packet; and

signaling that the network element serves both a security gateway functionality and a serving gateway functionality if the first destination IP address and the second destination IP address are identical.

18. The non-transitory machine-readable storage medium of claim 17 , wherein the first destination IP address is associated with the network element, and wherein the second destination IP address is associated with the network element or a serving gateway of the core packet network.

19. The non-transitory machine-readable storage medium of claim 17 , wherein exchanging further packets with the eNB comprises receiving a third packet from the eNB via an IPsec transport mode, wherein the third packet includes a third IP header identical to the second IP header without encapsulating another IP header therein.

20. The non-transitory machine-readable storage medium of claim 17 , wherein the method further comprises:

performing a general packet radio service (GPRS) tunnel protocol (GTP) process on a payload of the second packet; and

transmitting a result of the GTP process to a packet data network (PDN) gateway of the core packet network.

21. The non-transitory machine-readable storage medium of claim 15 , wherein the network element is located at an edge of the core packet network interfacing one or more eNBs with the core packet network.

Assignments (26)
RELEASE OF SECURITY INTEREST IN COLLATERAL RECORDED AT REEL 069113 AND FRAME 0558 Recorded Jul 31, 2025
From: GLAS USA LLC
To: MAVENIR SYSTEMS, INC.
Reel/Frame 072308/0172 →
RELEASE OF SECURITY INTEREST IN COLLATERAL RECORDED AT REEL 067565 AND FRAME 0678 Recorded Jul 29, 2025
From: WILMINGTON SAVINGS FUND SOCIETY, FSB
To: MAVENIR SYSTEMS, INC.
Reel/Frame 072263/0421 →
RELEASE OF SECURITY INTERESTS (SYNDICATED) Recorded Jul 29, 2025
From: JPMORGAN CHASE BANK, N.A.
To: MAVENIR SYSTEMS, INC.
Reel/Frame 072263/0121 →
RELEASE OF SECURITY INTERESTS (SIDECAR) Recorded Jul 29, 2025
From: JPMORGAN CHASE BANK, N.A.
To: MAVENIR SYSTEMS, INC.
Reel/Frame 072263/0041 →
GRANT OF SECURITY INTEREST - PATENTS Recorded Jul 29, 2025
From: MAVENIR NETWORKS, INC.; MAVENIR SYSTEMS, INC.; ARGYLE DATA, INC.; MAVENIR, INC.; AQUTO CORPORATION; MAVENIR IPA UK LIMITED; MAVENIR SYSTEMS UK LIMITED; MAVENIR LTD.; MAVENIR US INC.
To: GLAS USA LLC
Reel/Frame 072245/0764 →
SECURITY INTEREST Recorded Jul 28, 2025
From: MAVENIR NETWORKS, INC.; MAVENIR SYSTEMS, INC.; ARGYLE DATA, INC.; MAVENIR, INC.; AQUTO CORPORATION; MAVENIR IPA UK LIMITED; MAVENIR SYSTEMS UK LIMITED; MAVENIR LTD.; MAVENIR US INC.
To: BLUE TORCH FINANCE LLC
Reel/Frame 072268/0439 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 032409/0858 Recorded May 15, 2025
From: FIRST-CITIZENS BANK & TRUST AS SUCCESSOR IN INTEREST TO SILICON VALLEY BANK
To: MAVENIR SYSTEMS, INC. AS SUCCESSOR IN INTEREST TO STOKE, INC.
Reel/Frame 071279/0767 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 4, 2024
From: MAVENIR SYSTEMS, INC.
To: GLAS USA LLC
Reel/Frame 069113/0558 →
RELEASE OF SECURITY INTEREST Recorded Oct 4, 2024
From: WILMINGTON SAVINGS FUND SOCIETY, FSB
To: MAVENIR SYSTEMS, INC.
Reel/Frame 069113/0596 →
SECURITY INTEREST Recorded Aug 30, 2024
From: MAVENIR SYSTEMS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 068822/0966 →
SECURITY INTEREST Recorded May 29, 2024
From: MAVENIR SYSTEMS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 067565/0678 →
SECURITY AGREEMENT Recorded Jul 13, 2022
From: MAVENIR SYSTEMS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 060641/0242 →
SECURITY AGREEMENT Recorded Aug 18, 2021
From: MAVENIR SYSTEMS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 057221/0801 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL - RELEASE OF 046139.0299 Recorded Aug 18, 2021
From: GOLDMAN SACHS LENDING PARTNERS LLC, AS COLLATERAL AGENT
To: MAVENIR SYSTEMS, INC.
Reel/Frame 057222/0398 →
GRANT OF SECURITY INTEREST IN PATENTS Recorded May 14, 2018
From: MAVENIR SYSTEMS, INC.
To: GOLDMAN SACHS LENDING PARTNERS LLC, AS COLLATERAL AGENT
Reel/Frame 046139/0299 →
RELEASE OF SECURITY INTEREST Recorded May 10, 2018
From: CERBERUS BUSINESS FINANCE, LLC, AS COLLATERAL AGENT
To: MAVENIR SYSTEMS, INC. (F/K/A MITEL MOBILITY INC.)
Reel/Frame 045773/0100 →
CHANGE OF NAME Recorded Apr 21, 2017
From: MITEL MOBILITY INC.
To: MAVENIR SYSTEMS, INC.
Reel/Frame 042369/0185 →
GRANT OF A SECURITY INTEREST -- PATENTS Recorded Mar 3, 2017
From: MAVENIR SYSTEMS, INC. (F/K/A MITEL MOBILITY INC.)
To: CERBERUS BUSINESS FINANCE, LLC, AS COLLATERAL AGENT
Reel/Frame 041877/0881 →
PARTIAL RELEASE OF SECURITY INTEREST IN PATENTS Recorded Mar 2, 2017
From: BANK OF AMERICA, N.A.
To: MITEL MOBILITY INC. (F/K/A MAVENIR SYSTEMS, INC.)
Reel/Frame 041868/0256 →
SECURITY INTEREST Recorded Mar 22, 2016
From: MITEL MOBILITY INC.
To: BANK OF AMERICA, N.A., AS THE COLLATERAL AGENT
Reel/Frame 038056/0269 →
MERGER AND CHANGE OF NAME Recorded Oct 22, 2015
From: MAVENIR INTERNATIONAL HOLDINGS, INC.; MITEL MOBILITY INC.
To: MITEL MOBILITY INC.
Reel/Frame 036861/0463 →
RELEASE OF SECURITY INTEREST Recorded May 1, 2015
From: SILICON VALLEY BANK
To: MAVENIR SYSTEMS, INC.; MAVENIR HOLDINGS, INC.; MAVENIR INTERNATIONAL HOLDINGS, INC. FKA STOKE, INC.; MAVENIR SYSTEMS IP HOLDINGS, LLC
Reel/Frame 035551/0171 →
MERGER Recorded Apr 10, 2015
From: STOKE, INC.
To: MAVENIR INTERNAITONAL HOLDINGS, INC.
Reel/Frame 035381/0064 →
SECURITY AGREEMENT Recorded Nov 20, 2014
From: MAVENIR INTERNATIONAL HOLDINGS, INC. (F/K/A STOKE, INC.)
To: SILICON VALLEY BANK
Reel/Frame 034332/0640 →
SECURITY INTEREST Recorded Mar 12, 2014
From: STOKE, INC.
To: SILICON VALLEY BANK
Reel/Frame 032409/0858 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2010
From: KANT, NISHI; LIM, HEESEON
To: STOKE, INC., A DELAWARE CORPORATION
Reel/Frame 023979/0633 →