IP Library Granted Patent US 11,689,502
Granted Patent B2
US 11,689,502 · App. 16/917,490 · Granted Jun 27, 2023

Securing control and user plane separation in mobile networks

Inventors: Leonid Burakovsky (Pleasanton, CA); Sachin Verma (Danville, CA); Fengliang Hu (Cupertino, CA); I-Chun Chen (Santa Clara, CA); How Tung Lim (San Jose, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/0263H04L61/5007H04L63/10H04L63/1458H04L63/1466H04L63/20H04W12/122H04W24/08H04L2463/141H04W80/02H04W84/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,689,502
App. No.
16/917,490
Filed
Jun 30, 2020
Granted
Jun 27, 2023
Kind
B2
Examiner
NIPA, WASIKA
Art Unit
2433
USPC
726/1
Abstract

Techniques for securing control and user plane separation in mobile networks (e.g., service provider networks for mobile subscribers, such as for 4G/5G networks) are disclosed. In some embodiments, a system/process/computer program product for securing control and user plane separation in mobile networks in accordance with some embodiments includes monitoring network traffic on a mobile network at a security platform to identify an Packet Forwarding Control Protocol (PFCP) message associated with a new session, in which the mobile network includes a 4G network or a 5G network; extracting a plurality of parameters from the PFCP message at the security platform; and enforcing a security policy at the security platform on the new session based on one or more of the plurality of parameters to secure control and user plane separation in the mobile network.

Claims (64)

1. A system, comprising:

a processor configured to:

monitor network traffic on a mobile network at a security platform to identify a Packet Forwarding Control Protocol (PFCP) message associated with a new session, wherein the mobile network includes a 4G network or a 5G network, wherein the security platform is configured to perform detection and prevention of Denial of Service (DoS) attacks for securing control and user plane separation in the mobile network;

extract a plurality of parameters from the PFCP message at the security platform, wherein the plurality of parameters include an IPv4 address and/or an IPv6 address, together with a Tunnel Endpoint Identifier (TEID) range;

enforce a security policy at the security platform on the new session based on one or more of the plurality of parameters to secure control and user plane separation in the mobile network, comprising to:

determine whether the TEID range, and the IPv4 address and/or IPv6 address of the plurality of parameters match a TEID range together with an IPv4 address and/or an IPv6 address of a tunnel to be set up; and

in response to a determination that the TEID range, and the IPv4 address and/or IPv6 address of the plurality of parameters match the TEID range together with the IPv4 address and/or the IPv6 address of the tunnel to be set up, allow the tunnel to be set up; and

parse the PFCP message to extract a source IP address, Session Endpoint Identifier (SEID) 1, a destination IP address, SEID 2, and a protocol in use related to a PFCP association; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system recited in claim 1 , wherein the plurality of parameters extracted from the PFCP message at the security platform include a source IP address, Session Endpoint Identifier (SEID) 1, a destination IP address, SEID 2, and a protocol in use.

3. The system recited in claim 1 , wherein the security platform is configured with a plurality of security policies to secure control and user plane separation in the mobile network.

4. The system recited in claim 1 , wherein the processor is further configured to:

parse the PFCP message to extract a Node ID related to a PFCP association.

5. The system recited in claim 1 , wherein the security platform monitors network traffic to and/or in a core network for a 5G network to secure control and user plane separation in the mobile network.

6. The system recited in claim 1 , wherein the security platform is configured to perform detection and prevention of Session Endpoint Identifier (SEID) Spoofing attacks for securing control and user plane separation in the mobile network.

7. The system recited in claim 1 , wherein the processor is further configured to:

block the new session from accessing a resource based on the security policy.

8. The system recited in claim 1 , wherein the processor is further configured to:

allow the new session to access a resource based on the security policy.

9. A method, comprising:

monitoring network traffic on a mobile network at a security platform to identify a Packet Forwarding Control Protocol (PFCP) message associated with a new session, wherein the mobile network includes a 4G network or a 5G network, wherein the security platform is configured to perform detection and prevention of Denial of Service (DoS) attacks for securing control and user plane separation in the mobile network;

extracting a plurality of parameters from the PFCP message at the security platform, wherein the plurality of parameters include an IPv4 address and/or an IPv6 address, together with a Tunnel Endpoint Identifier (TEID) range;

enforcing a security policy at the security platform on the new session based on one or more of the plurality of parameters to secure control and user plane separation in the mobile network, comprising:

determining whether the TEID range, and the IPv4 address and/or IPv6 address of the plurality of parameters match a TEID range together with an IPv4 address and/or an IPv6 address of a tunnel to be set up; and

in response to a determination that the TEID range, and the IPv4 address and/or IPv6 address of the plurality of parameters match the TEID range together with the IPv4 address and/or the IPv6 address of the tunnel to be set up, allowing the tunnel to be set up; and

parsing the PFCP message to extract a source IP address, Session Endpoint Identifier (SEID) 1, a destination IP address, SEID 2, and a protocol in use related to a PFCP association.

10. The method of claim 9 , wherein the plurality of parameters extracted from the PFCP message at the security platform include a source IP address, Session Endpoint Identifier (SEID) 1, a destination IP address, SEID 2, and a protocol in use.

11. The method of claim 9 , wherein the security platform is configured with a plurality of security policies to secure control and user plane separation in the mobile network.

12. The method of claim 9 , further comprising:

parsing the PFCP message to extract a Node ID related to a PFCP association.

13. The method of claim 9 , wherein the security platform monitors network traffic to and/or in a core network for a 5G network to secure control and user plane separation in the mobile network.

14. The method of claim 9 , wherein the security platform is configured to perform detection and prevention of Session Endpoint Identifier (SEID) Spoofing attacks for securing control and user plane separation in the mobile network.

15. The method of claim 9 , further comprising:

allowing or blocking the new session from accessing a resource based on the security policy.

16. A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

monitoring network traffic on a mobile network at a security platform to identify a Packet Forwarding Control Protocol (PFCP) message associated with a new session, wherein the mobile network includes a 4G network or a 5G network, wherein the security platform is configured to perform detection and prevention of Denial of Service (DoS) attacks for securing control and user plane separation in the mobile network;

extracting a plurality of parameters from the PFCP message at the security platform, wherein the plurality of parameters include an IPv4 address and/or an IPv6 address, together with a Tunnel Endpoint Identifier (TEID) range;

enforcing a security policy at the security platform on the new session based on one or more of the plurality of parameters to secure control and user plane separation in the mobile network, comprising:

determining whether the TEID range, and the IPv4 address and/or IPv6 address of the plurality of parameters match a TEID range together with an IPv4 address and/or an IPv6 address of a tunnel to be set up; and

in response to a determination that the TEID range, and the IPv4 address and/or IPv6 address of the plurality of parameters match the TEID range together with the IPv4 address and/or the IPv6 address of the tunnel to be set up, allowing the tunnel to be set up; and

parsing the PFCP message to extract a source IP address, Session Endpoint Identifier (SEID) 1 , a destination IP address, SEID 2, and a protocol in use related to a PFCP association.

17. A system, comprising:

a processor configured to:

monitor network traffic on a mobile network at a security platform to identify a Packet Forwarding Control Protocol (PFCP) message associated with a new session, wherein the mobile network includes a 4G network or a 5G network, wherein the security platform is configured to perform detection and prevention of Session Endpoint Identifier (SEID) Spoofing attacks for securing control and user plane separation in the mobile network;

extract a plurality of parameters from the PFCP message at the security platform, wherein the plurality of parameters include an IPv4 address and/or an IPv6 address, together with a Tunnel Endpoint Identifier (TEID) range;

enforce a security policy at the security platform on the new session based on one or more of the plurality of parameters to secure control and user plane separation in the mobile network, comprising to:

determine whether the TEID range, and the IPv4 address and/or IPv6 address of the plurality of parameters match a TEID range together with an IPv4 address and/or an IPv6 address of a tunnel to be set up; and

in response to a determination that the TEID range, and the IPv4 address and/or IPv6 address of the plurality of parameters match the TEID range together with the IPv4 address and/or the IPv6 address of the tunnel to be set up, allow the tunnel to be set up; and

parse the PFCP message to extract a source IP address, Session Endpoint Identifier (SEID) 1, a destination IP address, SEID 2, and a protocol in use related to a PFCP association; and

a memory coupled to the processor and configured to provide the processor with instructions.

18. A method, comprising:

monitoring network traffic on a mobile network at a security platform to identify a Packet Forwarding Control Protocol (PFCP) message associated with a new session, wherein the mobile network includes a 4G network or a 5G network, wherein the security platform is configured to perform detection and prevention of Session Endpoint Identifier (SEID) Spoofing attacks for securing control and user plane separation in the mobile network;

extracting a plurality of parameters from the PFCP message at the security platform, wherein the plurality of parameters include an IPv4 address and/or an IPv6 address, together with a Tunnel Endpoint Identifier (TEID) range;

enforcing a security policy at the security platform on the new session based on one or more of the plurality of parameters to secure control and user plane separation in the mobile network, comprising:

determining whether the TEID range, and the IPv4 address and/or IPv6 address of the plurality of parameters match a TEID range together with an IPv4 address and/or an IPv6 address of a tunnel to be set up; and

in response to a determination that the TEID range, and the IPv4 address and/or IPv6 address of the plurality of parameters match the TEID range together with the IPv4 address and/or the IPv6 address of the tunnel to be set up, allowing the tunnel to be set up; and

parsing the PFCP message to extract a source IP address, Session Endpoint Identifier (SEID) 1 , a destination IP address, SEID 2, and a protocol in use related to a PFCP association.

19. A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

monitoring network traffic on a mobile network at a security platform to identify a Packet Forwarding Control Protocol (PFCP) message associated with a new session, wherein the mobile network includes a 4G network or a 5G network, wherein the security platform is configured to perform detection and prevention of Session Endpoint Identifier (SEID) Spoofing attacks for securing control and user plane separation in the mobile network;

extracting a plurality of parameters from the PFCP message at the security platform, wherein the plurality of parameters include an IPv4 address and/or an IPv6 address, together with a Tunnel Endpoint Identifier (TEID) range; and

enforcing a security policy at the security platform on the new session based on one or more of the plurality of parameters to secure control and user plane separation in the mobile network, comprising:

determining whether the TEID range, and the IPv4 address and/or IPv6 address of the plurality of parameters match a TEID range together with an IPv4 address and/or an IPv6 address of a tunnel to be set up; and

in response to a determination that the TEID range, and the IPv4 address and/or IPv6 address of the plurality of parameters match the TEID range together with the IPv4 address and/or the IPv6 address of the tunnel to be set up, allowing the tunnel to be set up; and

parsing the PFCP message to extract a source IP address, Session Endpoint Identifier (SEID) 1, a destination IP address, SEID 2, and a protocol in use related to a PFCP association.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 10, 2020
From: BURAKOVSKY, LEONID; VERMA, SACHIN; HU, FENGLIANG; CHEN, I-CHUN; LIM, HOW TUNG
To: PALO ALTO NETWORKS, INC.
Reel/Frame 053449/0977 →
Continuity (1)
Related Publication 20210409375A1 · Dec 30, 2021
Cited By (8)
US 12,375,922 US 12,463,989 US 12,476,948 US 12,526,633 US 12,563,398 US 12,574,405 US 12,574,734 US 12,677,153