IP Library › Granted Patent US 11,606,691
Granted Patent B1
US 11,606,691 · App. 17/681,494 · Granted Mar 14, 2023

Context-based security over interfaces in O-RAN environments in mobile networks

Inventors: Sachin Verma (Danville, CA); Leonid Burakovsky (Pleasanton, CA)
Assignee: Palo Alto Networks, Inc.
H04W12/088H04W12/033H04W12/30H04W12/60H04W24/08H04W76/12H04W80/12H04W84/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,606,691
App. No.
17/681,494
Granted
Mar 14, 2023
Kind
B1
Abstract

Techniques for applying context-based security over interfaces in O-RAN environments in mobile networks are disclosed. In some embodiments, a system/process/computer program product for applying context-based security over interfaces in O-RAN environments in mobile networks includes monitoring network traffic on a mobile network at a security platform to identify a GTP-U tunnel session setup message associated with a new session; extracting a plurality of parameters from the GTP-U tunnel session setup message and from F1AP traffic to extract contextual information at the security platform; and enforcing a security policy at the security platform on the new session based on one or more of the plurality of parameters to apply context-based security to the network traffic transported between O-RAN Distributed Unit (O-DU) and O-RAN Centralized Unit Control Plane (O-CU-CP) nodes in an O-RAN environment in the mobile network.

Claims (51)

1. A system, comprising:

a processor configured to:

monitor network traffic on a mobile network at a security platform to identify a GTP-U tunnel session setup message associated with a new session;

extract a plurality of parameters from the GTP-U tunnel session setup message and from F1AP traffic to extract contextual information at the security platform, wherein extracting a plurality of parameters from the GTP-U tunnel session setup message and from F1AP traffic to extract contextual information at the security platform further comprises:

extract User Plane (UP) transport layer information from a UE CONTEXT SETUP REQUEST and UE CONTEXT SETUP RESPONSE messages exchanged between gNB-DU and gNB-CU nodes during a UE Context Setup Procedure to set up the GTP-U tunnel session;

inspect F1AP traffic over an F1-C interface between O-RAN Distributed Unit (O-DU) and O-RAN Centralized Unit Control Plane (O-CU-CP) nodes in an O-RAN environment in the mobile network to extract contextual information; and

inspect GTP-U traffic over an F1-U interface between the O-DU and O-RAN Centralized Unit User Plane (O-CU-UP) nodes for applying layer-7 security on User Plane (UP) traffic; and

enforce a security policy at the security platform on the new session based on one or more of the plurality of parameters to apply context-based security to the network traffic transported between the O-DU and the O-CU-CP nodes and between the O-DU and the O-CU-UP nodes in the O-RAN environment in the mobile network; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system recited in claim 1 , wherein the security platform extracts User Plane (UP) transport layer information extracted from a handover request message to setup the GTP-U tunnel session.

3. The system recited in claim 1 , wherein the security platform is configured with a plurality of security policies to apply the context-based security to the network traffic transported between the O-DU node and the O-CU-CP node in the O-RAN environment in the mobile network.

4. The system recited in claim 1 , wherein the processor is further configured to:

inspect F1AP traffic over an F1-C interface between the O-DU node and the O-CU-CP node to extract the contextual information.

5. The system recited in claim 1 , wherein the processor is further configured to:

inspect F1AP traffic over an F1-C interface between the O-DU node and the O-CU-CP node to extract the contextual information; and

store the contextual information locally in the security platform or in a cloud-based storage.

6. The system recited in claim 1 , wherein the processor is further configured to:

inspect GTP-U traffic over an F1-U interface between a gNB-DU node and a gNB-CU node to apply Layer-7 security on user plane traffic; and

correlate the context information with user plane traffic to perform context-based security for inter node traffic in the O-RAN environment.

7. The system recited in claim 1 , wherein the security platform is configured to perform context-based security over an F1-U interface in the O-RAN environment.

8. The system recited in claim 1 , wherein the security platform is configured to perform detection and prevention of known and unknown threat identification and prevention over an F1-U interface in the O-RAN environment.

9. The system recited in claim 1 , wherein the security platform is configured to perform application identification and control over an F1-U interface in the O-RAN environment.

10. The system recited in claim 1 , wherein the security platform is configured to perform URL filtering over an F1-U interface in the O-RAN environment.

11. The system recited in claim 1 , wherein the processor is further configured to:

block the new session from accessing a resource based on the security policy.

12. The system recited in claim 1 , wherein the processor is further configured to:

allow the new session to access a resource based on the security policy.

13. A method, comprising:

monitoring network traffic on a mobile network at a security platform to identify a GTP-U tunnel session setup message associated with a new session;

extracting a plurality of parameters from the GTP-U tunnel session setup message and from F1AP traffic to extract contextual information at the security platform, wherein extracting a plurality of parameters from the GTP-U tunnel session setup message and from F1AP traffic to extract contextual information at the security platform further comprises:

extracting User Plane (UP) transport layer information from a UE CONTEXT SETUP REQUEST and UE CONTEXT SETUP RESPONSE messages exchanged between gNB-DU and gNB-CU nodes during a UE Context Setup Procedure to set up the GTP-U tunnel session;

inspecting F1AP traffic over an F1-C interface between O-RAN Distributed Unit (O-DU) and O-RAN Centralized Unit Control Plane (O-CU-CP) nodes in an O-RAN environment in the mobile network to extract contextual information; and

inspecting GTP-U traffic over an F1-U interface between the O-DU and O-RAN Centralized Unit User Plane (O-CU-UP) nodes for applying layer-7 security on User Plane (UP) traffic; and

enforcing a security policy at the security platform on the new session based on one or more of the plurality of parameters to apply context-based security to the network traffic transported between the O-DU and the O-CU-CP nodes and between the O-DU and the O-CU-UP nodes in the O-RAN environment in the mobile network.

14. The method of claim 13 , wherein the security platform extracts User Plane (UP) transport layer information extracted from a handover request message to setup the GTP-U tunnel session.

15. The method of claim 13 , wherein the security platform is configured with a plurality of security policies to apply the context-based security to the network traffic transported between the O-DU node and the O-CU-CP node in the O-RAN environment in the mobile network.

16. The method of claim 13 , further comprising:

inspecting F1AP traffic over an F1-C interface between the O-DU node and the O-CU-CP node to extract the contextual information.

17. The method of claim 13 , further comprising:

inspecting GTP-U traffic over an F1-U interface between a gNB-DU node and a gNB-CU node to apply Layer-7 security on user plane traffic.

18. The method of claim 13 , further comprising:

correlating the context information with user plane traffic to perform context-based security for inter node traffic in the O-RAN environment.

19. The method of claim 13 , further comprising:

performing context-based security over an F1-U interface in the O-RAN environment.

20. A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

monitoring network traffic on a mobile network at a security platform to identify a GTP-U tunnel session setup message associated with a new session;

extracting a plurality of parameters from the GTP-U tunnel session setup message and from F1AP traffic to extract contextual information at the security platform, wherein extracting a plurality of parameters from the GTP-U tunnel session setup message and from F1AP traffic to extract contextual information at the security platform further comprises:

extracting User Plane (UP) transport layer information from a UE CONTEXT SETUP REQUEST and UE CONTEXT SETUP RESPONSE messages exchanged between gNB-DU and gNB-CU nodes during a UE Context Setup Procedure to set up the GTP-U tunnel session;

inspecting F1AP traffic over an F1-C interface between O-RAN Distributed Unit (O-DU) and O-RAN Centralized Unit Control Plane (O-CU-CP) nodes in an O-RAN environment in the mobile network to extract contextual information; and

inspecting GTP-U traffic over an F1-U interface between the O-DU and O-RAN Centralized Unit User Plane (O-CU-UP) nodes for applying layer-7 security on User Plane (UP) traffic; and

enforcing a security policy at the security platform on the new session based on one or more of the plurality of parameters to apply context-based security to the network traffic transported between the O-DU and the O-CU-CP nodes and between the O-DU and the O-CU-UP nodes in the O-RAN environment in the mobile network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 24, 2022
From: VERMA, SACHIN; BURAKOVSKY, LEONID
To: PALO ALTO NETWORKS, INC.
Reel/Frame 060006/0977 →
Cited By (4)
US 12,676,896 US 12,684,357 US 12,695,791 US 12,695,792