IP Library › Granted Patent US 12,487,847
Granted Patent B2
US 12,487,847 · App. 18/300,641 · Granted Dec 2, 2025

Virtual firewall for use in a private mobile core

Inventor: Tarun Chaki (Morganville, NJ)
Assignee: AT&T Intellectual Property I, L.P.
G06F9/45558H04W12/088G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,487,847
App. No.
18/300,641
Granted
Dec 2, 2025
Kind
B2
Abstract

Aspects of the subject disclosure may include, for example, a method that includes deploying a first virtual machine configured to implement a plurality of control plane network functions in a wireless network, deploying a second virtual machine configured to implement a user plane function in the wireless network, deploying a third virtual machine configured to implement firewall functions, and deploying the first virtual machine, the second virtual machine and the third virtual machine on an on-premises host server. Other embodiments are disclosed.

Claims (57)

1 . A device, comprising:

a processing system including a processor; and

a memory that stores executable instructions that, when executed by the processing system, facilitate performance of operations, the operations comprising:

deploying a first virtual machine configured to implement a plurality of control plane network functions in a wireless network;

deploying a second virtual machine configured to implement a user plane function in the wireless network;

deploying a third virtual machine configured to implement firewall functions, wherein the deploying the third virtual machine comprises deploying the third virtual machine to be in-line with the first virtual machine and the second virtual machine such that a first network traffic flows between a base station and the first virtual machine through the third virtual machine, a second network traffic flows between the base station and the second virtual machine through the third virtual machine, a third network traffic flows between the first virtual machine and the second virtual machine, or a combination thereof; and

deploying the first virtual machine, the second virtual machine and the third virtual machine on a host server arranged at a user premises.

2 . The device of claim 1 , wherein the operations further comprise:

service-chaining the plurality of control plane network functions and the user plane function via the third virtual machine.

3 . The device of claim 2 , wherein the service-chaining further comprises:

setting a first static route in the first virtual machine to pass through the third virtual machine; and

setting a second static route in the second virtual machine to pass through the third virtual machine.

4 . The device of claim 1 , wherein:

the deploying the first virtual machine further comprises implementing access and mobility function (AMF) in the first virtual machine; and

the operations further comprise directing N2 traffic between the base station and the AMF to pass through the third virtual machine.

5 . The device of claim 4 , wherein the operations further comprise directing N3 traffic between the base station and the user plane function to pass through the third virtual machine.

6 . The device of claim 5 , wherein:

the deploying the first virtual machine further comprises implementing session management function (SMF) in the first virtual machine; and

the operations further comprise directing N4 traffic between the SMF and the user plane function to pass through the third virtual machine.

7 . The device of claim 6 , wherein the operations further comprise:

analyzing the N2 traffic, the N3 traffic and the N4 traffic at the third virtual machine;

determining a presence of an anomaly by correlating the N2 traffic, the N3 traffic, the N4 traffic, or a combination thereof, and

upon determination that the anomaly is present, generating an action.

8 . The device of claim 1 , wherein the operations further comprise deploying the third virtual machine at a first interface between one or more of the control plane network functions and the base station and at a second interface between the user plane function and the base station.

9 . The device of claim 1 , wherein the deploying the third virtual machine further comprises loading a policy and a set of rules dictating network traffic flow and a security level in the third virtual machine.

10 . The device of claim 1 , wherein the operations further comprise:

analyzing threats posed by the first network traffic, the second network traffic, the third network traffic, or a combination thereof, by performing a correlation among the first network traffic, the second network traffic and the third network traffic; and

matching information from the second network traffic against information from the third network traffic.

11 . The device of claim 10 , wherein the operations further comprise:

based on the correlation, determining an anomaly in usage of network resources; and

blocking a network traffic determined to be relevant to the anomaly among the first network traffic, the second network traffic, the third network traffic, or a combination thereof.

12 . A non-transitory machine-readable medium, comprising executable instructions that, when executed by a processing system including a processor, facilitate performance of operations, the operations comprising:

deploying a first virtual machine configured to contain a plurality of control plane network functions in a wireless network;

deploying a second virtual machine configured to contain a user plane function in the wireless network;

deploying a third virtual machine configured to contain firewall functions, wherein the deploying the third virtual machine comprises deploying the third virtual machine to be in-line such that first network traffic flow between a base station and the first virtual machine through the third virtual machine, second network traffic flow between the base station and the second virtual machine through the third virtual machine, third network traffic flow between the first virtual machine and the second virtual machine, or a combination thereof; and

deploying the first virtual machine, the second virtual machine and the third virtual machine on a host server arranged at a user premises.

13 . The non-transitory machine-readable medium of claim 12 , wherein the operations further comprise deploying the third virtual machine simultaneously at a first interface between one or more of the control plane network functions and the base station and at a second interface between the user plane function and the base station.

14 . The non-transitory machine-readable medium of claim 12 , wherein the operations further comprise:

service-chaining the plurality of control plane network functions and the user plane function via the third virtual machine; and

setting a plurality of static routes in the first virtual machine and in the second virtual machine to pass through the third virtual machine.

15 . A method, comprising:

deploying, by a processing system including a processor, a private mobile core on a host server located at a user premises, the deploying comprising:

deploying a first virtual machine configured to implement a plurality of control plane network functions in a wireless communication network; and

deploying a second virtual machine configured to implement a user plane function in the wireless communication network;

deploying, by the processing system, a third virtual machine configured to implement firewall functions on the host server, wherein the deploying the third virtual machine comprises deploying the third virtual machine to be in-line such that first network traffic flow between a base station and the first virtual machine through the third virtual machine, second network traffic flow between the base station and the second virtual machine through the third virtual machine, third network traffic flow between the first virtual machine and the second virtual machine, or a combination thereof; and

setting, by the processing system, one or more static routes of network traffic to pass through the third virtual machine while flowing between the base station and the private mobile core.

16 . The method of claim 15 , wherein the setting the one or more static routes further comprises:

directing, by the processing system, a first network traffic between the base station and the first virtual machine, a second network traffic between the first virtual machine and the second virtual machine, a third network traffic between the base station and the second virtual machine, or a combination thereof, to pass through the third virtual machine.

17 . The method of claim 16 , further comprising:

analyzing, by the processing system, threats posed by the first network traffic, the second network traffic, the third network traffic, or a combination thereof, by performing a correlation among the first network traffic, the second network traffic and the third network traffic.

18 . The method of claim 17 , wherein the performing the correlation further comprises matching, by the processing system, information from the second network traffic against information from the third network traffic.

19 . The method of claim 17 , further comprising:

based on the correlation, determining, by the processing system, an anomaly in usage of network resources; and

blocking, by the processing system, a network traffic determined to be relevant to the anomaly among the first network traffic, the second network traffic, the third network traffic, or a combination thereof.

20 . The method of claim 17 , further comprising:

based on the correlation, determining, by the processing system, a malicious traffic; and

blocking, by the processing system, a network traffic determined to be relevant to the malicious traffic among the first network traffic, the second network traffic, the third network traffic, or a combination thereof.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 4, 2023
From: CHAKI, TARUN
To: AT&T INTELLECTUAL PROPERTY I, L.P.
Reel/Frame 063530/0146 →
Continuity (1)
Related Publication 20240345861A1 · Oct 17, 2024
References Cited (15)
US 9569233B2 · Masters · 2017 [cited by examiner]
US 12267212B2 · Zhou · 2025 [cited by examiner]
US 20160381662A1 · Wang · 2016 [cited by examiner]
US 20170111274A1 · Bays · 2017 [cited by examiner]
US 20170168864A1 · Ross · 2017 [cited by examiner]
US 20210345108A1 · Li · 2021 [cited by examiner]
US 20220200801A1 · Potlapally · 2022 [cited by examiner]
US 20230336411A1 · Metkar · 2023 [cited by examiner]
US 20240056803A1 · Huang · 2024 [cited by examiner]
US 20240111603A1 · Krasilnikov · 2024 [cited by examiner]
CN 103870749A · 2014 [cited by examiner]
CN 107544835A · 2018 [cited by examiner]
CN 113543152A · 2021 [cited by examiner]
WO WO2016177207A1 · 2016 [cited by examiner]
WO WO2024057063A1 · 2024 [cited by examiner]