IP Library › Granted Patent US 12,689,900
Granted Patent B2
US 12,689,900 · App. 18/320,352 · Granted Jul 21, 2026

User equipment vulnerability management based traffic routing with multi access edge compute

Inventors: Robert Edgar Barton (Richmond, CA); Flemming Stig Andreasen (Marlboro, NJ)
Assignee: CISCO TECHNOLOGY, INC.
H04W12/12H04W12/033H04W28/0215
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,689,900
App. No.
18/320,352
Filed
May 19, 2023
Granted
Jul 21, 2026
Kind
B2
Art Unit
2641
USPC
455/411
Abstract

A method to counter vulnerabilities associated with user equipment in operating via a 5G core architecture. The method includes monitoring a session between a user equipment and an endpoint, obtaining a vulnerability score for a vulnerability affecting the user equipment, selecting, based on the vulnerability score, a selected user plane function and a security service, accessible via the selected user plane function, to counter the vulnerability affecting the user equipment, and causing a packet flow of the session to be steered to the security service via the selected user plane function.

Claims (35)

1 . A method comprising:

monitoring a session, through a mobile core network that includes an application function, between a user equipment and an endpoint;

obtaining a vulnerability score for a vulnerability affecting the user equipment;

selecting, based on a combination of the vulnerability score and a protocol data unit session policy set by the application function, a selected user plane function and a security service, accessible via the selected user plane function, to counter the vulnerability affecting the user equipment, wherein the selected user plane function is part of the mobile core network; and

causing a packet flow of the session to be steered to the security service via the selected user plane function.

2 . The method of claim 1 , wherein the session is a session being processed by the mobile core network.

3 . The method of claim 2 , wherein the method is performed, at least in part, by a session management function of the mobile core network.

4 . The method of claim 1 , further comprising obtaining the vulnerability score from a Common Vulnerability Scoring System.

5 . The method of claim 1 , wherein the selected user plane function operates as an uplink classifier and branching point.

6 . The method of claim 1 , wherein the selected user plane function operates as a local protocol data unit session anchor.

7 . The method of claim 1 , wherein the selected user plane function is selected based on at least one of latency to reach the security service and bandwidth to reach the security service.

8 . The method of claim 1 , wherein the security service is hosted by the selected user plane function.

9 . The method of claim 1 , wherein the security service is hosted by an edge application server.

10 . The method of claim 1 , further comprising tunneling the packet flow of the session to the security service.

11 . A device comprising:

an interface configured to enable network communications;

a memory; and

one or more processors coupled to the interface and the memory, and configured to:

monitor a session, through a mobile core network that includes an application function, between a user equipment and an endpoint;

obtain a vulnerability score for a vulnerability affecting the user equipment;

select, based on a combination of the vulnerability score and a protocol data unit session policy set by the application function, a selected user plane function and a security service, accessible via the selected user plane function, to counter the vulnerability affecting the user equipment, wherein the selected user plane function is part of the mobile core network; and

cause a packet flow of the session to be steered to the security service via the selected user plane function.

12 . The device of claim 11 , wherein the session is a session being processed by the mobile core network.

13 . The device of claim 12 , wherein the device is a session management function of the mobile core network.

14 . The device of claim 11 , wherein the one or more processors are further configured to obtain the vulnerability score from a Common Vulnerability Scoring System.

15 . The device of claim 11 , wherein the selected user plane function operates as an uplink classifier and branching point.

16 . The device of claim 11 , wherein the selected user plane function operates as a local protocol data unit (PDU) session anchor.

17 . The device of claim 11 , wherein the selected user plane function is selected based on at least one of latency to reach the security service and bandwidth to reach the security service.

18 . One or more non-transitory computer readable storage media encoded with instructions that, when executed by a processor, cause the processor to:

monitor a session, through a mobile core network that includes an application function, between a user equipment and an endpoint;

obtain a vulnerability score for a vulnerability affecting the user equipment;

select, based on a combination of the vulnerability score and a protocol data unit session policy set by the application function, a selected user plane function and a security service, accessible via the selected user plane function, to counter the vulnerability affecting the user equipment, wherein the selected user plane function is part of the mobile core network; and

cause a packet flow of the session to be steered to the security service via the selected user plane function.

19 . The one or more non-transitory computer readable storage media of claim 18 , wherein the processor is part of a session management function of the mobile core network.

20 . The one or more non-transitory computer readable storage media of claim 18 , wherein the instructions, when executed by the processor, are configured to obtain the vulnerability score from a Common Vulnerability Scoring System.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2023
From: BARTON, ROBERT EDGAR; ANDREASEN, FLEMMING STIG
To: CISCO TECHNOLOGY, INC.
Reel/Frame 063700/0460 →
Continuity (1)
Related Publication 20240388914A1 · Nov 21, 2024
References Cited (13)
US 10268474B2 · Stammers et al. · 2019 [cited by applicant]
US 10958556B2 · Rajalingam · 2021 [cited by examiner]
US 11765087B1 · Balmakhtar · 2023 [cited by examiner]
US 20070113080A1 · Shankar et al. · 2007 [cited by applicant]
US 20190238584A1 · Somasundaram et al. · 2019 [cited by applicant]
US 20200074085A1 · Cheng · 2020 [cited by examiner]
US 20220368717A1 · Mylavarapu et al. · 2022 [cited by applicant]
WO 2018075930A1 · 2018 [cited by applicant]
3GPP, Technical Specification, “5G; Procedures for the 5G System (5GS), (3GPP TS 23.502 version 16.7.0 Release 16),” ETSI TS 123 502 V16.7.0, 607 pages, Jan. 2021. [cited by applicant]
3GPP, Technical Specification, “5G; System architecture for the 5G System (5GS), (3GPP TS 23.501 version 16.6.0 Release 16),” ETSI TS 123 501 V16.6.0, 450 pages, Oct. 2020. [cited by applicant]
Kholidy, H., et al. “A Triangular Fuzzy based Multicriteria Decision Making Approach for Assessing Security Risks in 5G Networks,” Department of Networks and Computer Security, College of Engineering, State University o… [cited by applicant]
3GPP, Technical Specification, “5G; 5G System Enhancements for Edge Computing; Stage 2, (3GPP TS 23.548 version 17.2.0 Release 17),” ETSI TS 123 548 V17.2.0, 58 pages, May 2022. [cited by applicant]
3GPP, Technical Specification, 5G; Security architecture and procedures for 5G System, (3GPP TS 33.501 version 17.5.0 Release 17), ETSI TS 133 501 V17.5.0, 296 pages, May 2022. [cited by applicant]