IP Library Granted Patent US 12,395,843
Granted Patent B2
US 12,395,843 · App. 18/071,543 · Granted Aug 19, 2025

SASE services for private mobile network

Inventors: Anand Srinivas (San Francisco, CA); Xiao H. Gao (Chapel Hill, NC); Sameer Naik (San Jose, CA)
H04W12/086H04L12/4633H04L12/66H04L41/0654H04L41/0806H04L41/0895H04L41/122H04L41/5019H04L45/28H04L45/64H04L45/74H04L45/76H04L45/80H04L63/0272H04W8/18H04W12/06H04W12/08H04W12/35H04W16/18H04W24/04H04W36/30H04W40/24H04W40/246H04W76/12H04W84/045H04W88/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,395,843
App. No.
18/071,543
Granted
Aug 19, 2025
Kind
B2
Abstract

Some embodiments provide a method for implementing a software-defined private mobile network (SD-PMN) for an entity. At a physical location of the entity, the method deploys a first set of control plane components for the SD-PMN, the first set of control plane components including a security gateway, a user-plane function (UPF), an AMF (access and mobility management function), and an SMF (session management function). At an SD-WAN (software-defined wide area network) PoP (point of presence) belonging to a provider of the SD-PMN, the method deploys a second set of control plane components for the SD-PMN that includes a subscriber database that stores data associated with users of the SD-PMN. The method uses an SD-WAN edge router located at the physical location of the entity and a SD-WAN gateway located at the SD-WAN PoP to establish a connection from the physical location of the entity to the SD-WAN PoP.

Claims (35)

1. A method of providing access to a plurality of cloud-delivered services for a multi-tenant SD-PMN (software-defined private mobile network), the SD-PMN spanning at least a first site belonging to a first entity and a PMN-provider second site, the first entity's first site comprising a first portion of the SD-PMN that includes one or more physical access points for connecting a plurality of user devices at the first entity's first site to the SD-PMN and one or more data plane components of the SD-PMN, the method comprising:

at a gateway router deployed in the PMN-provider second site:

receiving a data message from a source located at the first entity's first site;

determining that the received data message should be processed by a service chain that performs a set of one or more cloud-delivered services before the data message is forwarded to a destination of the data message;

forwarding the data message to the service chain that performs the set of one or more cloud-delivered services for processing; and

upon receiving the processed data message from the service chain, forwarding the processed data message to the destination of the data message.

2. The method of claim 1 , wherein:

the PMN-provider second site comprises a SASE (secure access service edge) PoP (point of presence);

the service chain comprises a SASE service chain located in the SASE PoP; and

forwarding the data message to the service chain comprises forwarding the data message to the SASE service chain in the SASE PoP.

3. The method of claim 1 , wherein forwarding the data message to the service chain comprises forwarding the data message to a third site that hosts the service chain.

4. The method of claim 1 , wherein the source of the data message comprises a user device from the plurality of user devices at the first entity's first site.

5. The method of claim 4 , wherein receiving the data message from the source located at the first entity's first site comprises receiving the data message from an edge router deployed to the first entity's first site to perform data message forwarding within the first entity's first site and between the first entity's first site and a plurality of destinations external to the first entity's first site.

6. The method of claim 5 , wherein the data message traverses a set of elements between the user device and the edge router deployed to the first entity's first set, the set of elements comprising at least one physical access point deployed at the first entity's first site and a user plane function (UPF) deployed at the first entity's first site.

7. The method of claim 1 , wherein the SD-PMN is a multi-tenant SD-PMN, wherein the first entity is one of a plurality of entities serviced by the SD-PMN.

8. The method of claim 7 , wherein the first entity's first site is one of a plurality of sites belonging to the first entity.

9. The method of claim 8 , wherein each entity in the plurality of entities serviced by the SD-PMN has at least one site.

10. The method of claim 1 , wherein the set of one or more cloud-delivered services comprises a firewall, a secure web gateway, a zero-trust network access service, and a threat detection service.

11. A non-transitory machine readable medium storing a program for execution by a set of processing units, the program for a gateway router that provides access to a plurality of cloud-delivered services for a multi-tenant SD-PMN (software-defined private mobile network), the SD-PMN spanning at least a first site belonging to a first entity and a PMN-provider second site to which the gateway router is deployed, the first entity's first site comprising a first portion of the SD-PMN that includes one or more physical access points for connecting a plurality of user devices at the first entity's first site to the SD-PMN and one or more data plane components of the SD-PMN, the program comprising sets of instructions for:

receiving a data message from a source located at the first entity's first site;

determining that the received data message should be processed by a service chain that performs a set of one or more cloud-delivered services before the data message is forwarded to a destination of the data message;

forwarding the data message to the service chain that performs the set of one or more cloud-delivered services for processing; and

upon receiving the processed data message from the service chain, forwarding the processed data message to the destination of the data message.

12. The non-transitory machine readable medium of claim 11 , wherein:

the PMN-provider second site comprises a SASE (secure access service edge) PoP (point of presence);

the service chain comprises a SASE service chain located in the SASE PoP; and

the set of instructions forwarding the data message to the service chain comprises a set of instructions forwarding the data message to the SASE service chain in the SASE PoP.

13. The non-transitory machine readable medium of claim 11 , wherein the set of instructions forwarding the data message to the service chain comprises a set of instructions forwarding the data message to a third site that hosts the service chain.

14. The non-transitory machine readable medium of claim 11 , wherein the source of the data message comprises a user device from the plurality of user devices at the first entity's first site.

15. The non-transitory machine readable medium of claim 14 , wherein the set of instructions for receiving the data message from the source located at the first entity's first site comprises a set of instructions for receiving the data message from an edge router deployed to the first entity's first site to perform data message forwarding within the first entity's first site and between the first entity's first site and a plurality of destinations external to the first entity's first site.

16. The non-transitory machine readable medium of claim 15 , wherein the data message traverses a set of elements between the user device and the edge router deployed to the first entity's first set, the set of elements comprising at least one physical access point deployed at the first entity's first site and a user plane function (UPF) deployed at the first entity's first site.

17. The non-transitory machine readable medium of claim 11 , wherein the SD-PMN is a multi-tenant SD-PMN, wherein the first entity is one of a plurality of entities serviced by the SD-PMN.

18. The non-transitory machine readable medium of claim 17 , wherein the first entity's first site is one of a plurality of sites belonging to the first entity.

19. The non-transitory machine readable medium of claim 18 , wherein each entity in the plurality of entities serviced by the SD-PMN has at least one site.

20. The non-transitory machine readable medium of claim 11 , wherein the set of one or more cloud-delivered services comprises a firewall, a secure web gateway, a zero-trust network access service, and a threat detection service.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2025
From: VMWARE, LLC
To: VELOCLOUD NETWORKS, LLC
Reel/Frame 072326/0693 →
CHANGE OF NAME Recorded Feb 27, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 066692/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 30, 2023
From: SRINIVAS, ANAND; GAO, XIAO H.; NAIK, SAMEER
To: VMWARE, INC.
Reel/Frame 063169/0590 →
Continuity (2)
Provisional Application 63402057 · Aug 29, 2022
Related Publication 20240073694A1 · Feb 29, 2024
References Cited (36)
US 9450817B1 · Bahadur et al. · 2016 [cited by applicant]
US 9843624B1 · Taaghol et al. · 2017 [cited by applicant]
US 9866433B1 · Fakhouri et al. · 2018 [cited by applicant]
US 10523531B2 · Zuerner · 2019 [cited by applicant]
US 10887276B1 · Parulkar et al. · 2021 [cited by applicant]
US 11153406B2 · Sawant · 2021 [cited by examiner]
US 11188376B1 · Alexander et al. · 2021 [cited by applicant]
US 11375005B1 · Rolando et al. · 2022 [cited by applicant]
US 11599376B1 · Viswanathan et al. · 2023 [cited by applicant]
US 20170005983A1 · Doukhvalov et al. · 2017 [cited by applicant]
US 20180367578A1 · Verma et al. · 2018 [cited by applicant]
US 20190109821A1 · Clark et al. · 2019 [cited by applicant]
US 20200052969A1 · Xu et al. · 2020 [cited by applicant]
US 20200067831A1 · Spraggins et al. · 2020 [cited by applicant]
US 20210105225A1 · Stammers et al. · 2021 [cited by applicant]
US 20210152513A1 · Grayson et al. · 2021 [cited by applicant]
US 20210297891A1 · Berzin et al. · 2021 [cited by applicant]
US 20220060408A1 · Manickam et al. · 2022 [cited by applicant]
US 20220103597A1 · Gobena et al. · 2022 [cited by applicant]
US 20220166755A1 · Moore et al. · 2022 [cited by applicant]
US 20220182332A1 · Christofi et al. · 2022 [cited by applicant]
US 20220400053A1 · Liu et al. · 2022 [cited by applicant]
US 20230123775A1 · Sivakumar et al. · 2023 [cited by applicant]
Non-Published Commonly Owned Related International Patent Application PCT/US2023/031449 with similar specification, filed Aug. 29, 2023, 55 pages, VMware, Inc. [cited by applicant]
PCT International Search Report and Written Opinion, PCT/US2023/031449, Nov. 20, 2023, 13 pages. [cited by applicant]
Non-Published Commonly Owned Related U.S. Appl. No. 18/071,536 with similar specification, filed Nov. 29, 2022, 55 pages, VMware, Inc. [cited by applicant]
Non-Published Commonly Owned Related U.S. Appl. No. 18/071,537 with similar specification, filed Nov. 29, 2022, 56 pages, VMware, Inc. [cited by applicant]
Non-Published Commonly Owned Related U.S. Appl. No. 18/071,540 with similar specification, filed Nov. 29, 2022, 56 pages, VMware, Inc. [cited by applicant]
Non-Published Commonly Owned Related U.S. Appl. No. 18/071,542 with similar specification, filed Nov. 29, 2022, 55 pages, VMware, Inc. [cited by applicant]
Non-Published Commonly Owned U.S. Appl. No. 18/071,544, filed Nov. 29, 2022, 54 pages, VMware, Inc. [cited by applicant]
Non-Published Commonly Owned U.S. Appl. No. 18/071,545, filed Nov. 29, 2022, 54 pages, VMware, Inc. [cited by applicant]
Non-Published Commonly Owned U.S. Appl. No. 18/071,547, filed Nov. 29, 2022, 55 pages, VMware, Inc. [cited by applicant]
Non-Published Commonly Owned U.S. Appl. No. 18/071,549, filed Nov. 29, 2022, 54 pages, VMware, Inc. [cited by applicant]
Non-Published Commonly Owned U.S. Appl. No. 18/071,552, filed Nov. 29, 2022, 54 pages, VMware, Inc. [cited by applicant]
Non-Published Commonly Owned U.S. Appl. No. 18/071,553, filed Nov. 29, 2022, 55 pages, VMware, Inc. [cited by applicant]
Non-Published Commonly Owned U.S. Appl. No. 18/071,554, filed Nov. 29, 2022, 55 pages, VMware, Inc. [cited by applicant]