IP Library Granted Patent US 12,245,039
Granted Patent B2
US 12,245,039 · App. 18/347,158 · Granted Mar 4, 2025

Security system for managing 5G network traffic background

Inventor: Venson Shaw (Kirkland, WA)
Assignee: T-Mobile USA, Inc.
H04W12/121H04L63/20H04W28/09H04W72/542H04W72/56H04W84/042
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,245,039
App. No.
18/347,158
Granted
Mar 4, 2025
Kind
B2
Abstract

The technology includes a method performed by a system of a telecommunications network to manage network traffic of a 5G network. The system can instantiate a security system to sort incoming or outgoing network traffic at a perimeter of the 5G network into multiple groups that are each uniquely associated with multiple traffic types and multiple security levels. The system can inspect segments of data included in the incoming network traffic and sort multiple portions of the network traffic into the groups based in part on the inspection of the segments of the data. The system can dynamically adjust an available bandwidth of the 5G network based on each load of each of the groups and dispatch the portions of the network traffic in accordance with a traffic type and a security level of each of the groups.

Claims (63)

1. A method performed by a security system to manage network traffic of a telecommunications network, the method comprising:

causing the security system to sort incoming or outgoing network traffic at the telecommunications network into one of multiple groups that are each uniquely associated with one of multiple traffic types and one of multiple security levels,

wherein the multiple traffic types include a user traffic type, a control traffic type, and a management traffic type, and

wherein the multiple security levels include a high security level and a low security level, and

wherein each of multiple portions of the network traffic is included in a group that is associated with a matching traffic type and a matching security level;

dynamically adjusting an available bandwidth of the telecommunications network based on a load and a security level of each of the multiple groups including a first group associated with the control traffic type and the high security level, a second group associated with the control traffic type and the low security level, a third group associated with the user traffic type and the high security level, and a fourth group associated with the user traffic type and the low security level,

wherein the available bandwidth is preferentially adjusted for the first group over the second group or the third group over the fourth group; and

dispatching the multiple portions of the network traffic in accordance with a traffic type and a security level of each of the multiple groups,

wherein network traffic of the first group is dispatched preferentially over network traffic of the second group, and

wherein network traffic of the third group is dispatched preferentially over network traffic of the fourth group.

2. The method of claim 1 further comprising:

detecting a condition of the telecommunications network; and

in response to the condition, changing the available bandwidth allocated to the multiple groups.

3. The method of claim 1 further comprising:

dynamically adjusting a priority order of the multiple groups.

4. The method of claim 1 , wherein the high security level is associated with an emergency service and the low security level is associated with a non-emergency service.

5. The method of claim 1 , wherein a network security appliance includes the security system.

6. The method of claim 1 , wherein the available bandwidth is adjusted based on the load of each of the multiple groups relative to an expected load for the traffic type.

7. The method of claim 1 further comprising, prior to instantiating the security system:

detecting an elevated security risk for the telecommunications network, wherein the security system is instantiated in response to the elevated security risk.

8. The method of claim 1 further comprising:

detecting a change in a security threat level to the telecommunications network; and

in response to the change, terminating an instantiation of the security system upon dispatching an entirety of the network traffic.

9. The method of claim 1 , wherein dynamically adjusting the available bandwidth of the telecommunications network based on the load of each of the multiple groups comprises:

allocating a greater amount of bandwidth to a group containing a greater amount of high security level network traffic compared to another group that contains a lesser amount of high security level network traffic.

10. A security system comprising:

a processor; and

a memory coupled to the processor and configured to store instructions that, when executed by the processor, cause the security system to:

cause the security system to sort network traffic at a telecommunications network into one of multiple groups that are each uniquely associated with one of multiple traffic types and one of multiple priority levels,

wherein the multiple traffic types include a first traffic type, a second traffic type, and a third traffic type, and

wherein the multiple priority levels include a first level and a second level;

dynamically adjust an available bandwidth of the telecommunications network based on a load on and a security level of each of the multiple groups including a first group associated with the second traffic type and the first level, a second group associated with the second traffic type and the second level, a third group associated with the first traffic type and the first level, and a fourth group associated with the first traffic type and the second level,

wherein the available bandwidth is preferentially adjusted for the first group over the second group or the third group over the fourth group; and

dispatch the network traffic in accordance with a traffic type and a priority level of each of the multiple groups,

wherein network traffic of the first group is dispatched preferentially over network traffic of the second group, and

wherein network traffic of the third group is dispatched preferentially over network traffic of the fourth group.

11. The system of claim 10 further caused to, prior to sorting the network traffic into the multiple groups:

inspect segments of data included in the network traffic,

wherein the segments of the data contain addressing information required for the data to reach one or more intended destinations, and

wherein the network traffic is stored based on the addressing information.

12. The system of claim 10 , wherein the first level and the second level, correspond to a first security level and a low security level, respectively.

13. The system of claim 10 comprising a network security appliance that includes the processor and the memory.

14. The system of claim 10 further caused to:

detect a change in a condition of the telecommunications network; and

in response to the change, change the available bandwidth allocated to the multiple groups.

15. The system of claim 10 further caused to:

dynamically adjust a priority order of the multiple groups.

16. The system of claim 10 , wherein the first level is associated with an emergency service and the second level is associated with a non-emergency service.

17. At least one non-transitory computer readable medium, storing instructions, which when executed by at least one data processor, manages network traffic of a telecommunications network by performing operations, the operations comprising:

causing a security system to sort multiple portions of incoming or outgoing network traffic at the telecommunications network into one of multiple groups that are each uniquely associated with one of multiple traffic types and one of multiple security levels,

wherein the multiple traffic types include a first traffic type, a second traffic type, and a third traffic type,

wherein the multiple security levels include a first security level, a second security level, and a third security level;

dynamically adjusting an available bandwidth of the telecommunications network based on a load and a security level of each of the multiple groups including a first group associated with the second traffic type and the first security level, a second group associated with the second traffic type and the third security level, a third group associated with the first traffic type and the first security level, and a fourth group associated with the first traffic type and the third security level,

wherein the available bandwidth is preferentially adjusted for the first group over the second group or the third group over the fourth group; and

dispatching the multiple portions of the network traffic in accordance with a traffic type and a security level of each of the multiple groups,

wherein network traffic of the first group is dispatched preferentially over network traffic of the second group, and

wherein network traffic of the third group is dispatched preferentially over network traffic of the fourth group.

18. The computer readable medium of claim 17 , wherein the available bandwidth is adjusted based on the load of each of the multiple groups relative to an expected load for the traffic type.

19. The computer readable medium of claim 17 , further comprising:

detecting a change in a security threat level to the telecommunications network; and

in response to the detected change, terminating an instantiation of the security system upon dispatching an entirety of the sorted network traffic.

20. The computer readable medium of claim 17 , wherein dynamically adjusting the available bandwidth of the telecommunications network based on the load of each of the multiple groups comprises:

allocating a greater amount of bandwidth to a group containing a greater amount of first security level network traffic compared to another group that contains a lesser amount of first security level network traffic.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 6, 2023
From: SHAW, VENSON
To: T-MOBILE USA, INC.
Reel/Frame 064170/0790 →
Continuity (2)
Continuation 16921765 · Jul 6, 2020
Related Publication 20230345248A1 · Oct 26, 2023
References Cited (69)
US 6167445A · Gai et al. · 2000 [cited by applicant]
US 6457051B1 · Riddle · 2002 [cited by examiner]
US 6597658B1 · Simmons · 2003 [cited by applicant]
US 7321555B2 · Rodriguez et al. · 2008 [cited by applicant]
US 7565692B1 · Maria · 2009 [cited by applicant]
US 7596811B2 · Lloyd et al. · 2009 [cited by applicant]
US 7891001B1 · Greenawalt et al. · 2011 [cited by applicant]
US 7895353B2 · Jansson · 2011 [cited by applicant]
US 7895642B1 · Larson et al. · 2011 [cited by applicant]
US 8037519B2 · Kalofonos et al. · 2011 [cited by applicant]
US 8136149B2 · Freund · 2012 [cited by applicant]
US 8271774B1 · Nachenberg et al. · 2012 [cited by applicant]
US 8284780B2 · Sullivan et al. · 2012 [cited by applicant]
US 8615785B2 · Elrod et al. · 2013 [cited by applicant]
US 8619799B1 · Thodupunoori et al. · 2013 [cited by applicant]
US 8693345B2 · Lee et al. · 2014 [cited by applicant]
US 8750125B2 · Harmatos · 2014 [cited by applicant]
US 9516053B1 · Muddu et al. · 2016 [cited by applicant]
US 9635663B2 · Murphy · 2017 [cited by examiner]
US 11516670B2 · Shaw · 2022 [cited by applicant]
US 20010055283A1 · Beach · 2001 [cited by applicant]
US 20040122967A1 · Bressler et al. · 2004 [cited by applicant]
US 20040208131A1 · Rodriguez et al. · 2004 [cited by applicant]
US 20050129019A1 · Cheriton · 2005 [cited by applicant]
US 20050273850A1 · Freund · 2005 [cited by applicant]
US 20050281253A1 · Veijalainen et al. · 2005 [cited by applicant]
US 20060007936A1 · Shrum et al. · 2006 [cited by applicant]
US 20060092841A1 · Lloyd et al. · 2006 [cited by applicant]
US 20070022468A1 · Iijima et al. · 2007 [cited by applicant]
US 20070089165A1 · Wei et al. · 2007 [cited by applicant]
US 20070118894A1 · Bhatia · 2007 [cited by applicant]
US 20070211696A1 · Noble · 2007 [cited by applicant]
US 20070211697A1 · Noble · 2007 [cited by applicant]
US 20080031219A1 · Zou · 2008 [cited by applicant]
US 20080062876A1 · Giroux et al. · 2008 [cited by applicant]
US 20080089237A1 · Molen et al. · 2008 [cited by applicant]
US 20080198747A1 · Young et al. · 2008 [cited by applicant]
US 20080232304A1 · Mooney et al. · 2008 [cited by applicant]
US 20090059952A1 · Kalofonos et al. · 2009 [cited by applicant]
US 20090122699A1 · Alperovitch et al. · 2009 [cited by applicant]
US 20090219940A1 · Jansson · 2009 [cited by applicant]
US 20100208614A1 · Harmatos · 2010 [cited by applicant]
US 20100325272A1 · Lloyd et al. · 2010 [cited by applicant]
US 20110161399A1 · Agulnik et al. · 2011 [cited by applicant]
US 20120300754A1 · Rosenqvist et al. · 2012 [cited by applicant]
US 20120304277A1 · Li et al. · 2012 [cited by applicant]
US 20150089566A1 · Chesla · 2015 [cited by applicant]
US 20150134232A1 · Robinson · 2015 [cited by applicant]
US 20150341379A1 · Lefebvre et al. · 2015 [cited by applicant]
US 20150373043A1 · Wang et al. · 2015 [cited by applicant]
US 20160021600A1 · Keller et al. · 2016 [cited by applicant]
US 20170346609A1 · Li · 2017 [cited by examiner]
US 20180063195A1 · Nimmagadda et al. · 2018 [cited by applicant]
US 20180295138A1 · Harris · 2018 [cited by examiner]
US 20180295148A1 · Mayorgo · 2018 [cited by applicant]
US 20190199646A1 · Singh et al. · 2019 [cited by applicant]
US 20190207976A1 · Yadav et al. · 2019 [cited by applicant]
US 20190380037A1 · Lifshitz et al. · 2019 [cited by applicant]
US 20200329072A1 · Dubois et al. · 2020 [cited by applicant]
US 20210051175A1 · Lyle · 2021 [cited by applicant]
US 20210067419A1 · Adam et al. · 2021 [cited by applicant]
US 20210274416A1 · Jendli et al. · 2021 [cited by applicant]
US 20210328914A1 · Garg · 2021 [cited by examiner]
CN 104301895A · 2015 [cited by applicant]
CN 105471835A · 2016 [cited by applicant]
WO 2020210015A1 · 2020 [cited by applicant]
WO 2021152262A1 · 2021 [cited by applicant]
F. Pacheco, et al., “Towards the Deployment of Machine Learning Solutions in Network Traffic Classification: A Systematic Survey,” in IEEE Communications Surveys & Tutorials, vol. 21, No. 2, pp. 1988-2014, (Year: 2018). [cited by applicant]
I. Ahmad, S. Shahabuddin, T. Kumar, J. Okwuibe, A. Gurtov and M. Ylianttila, “Security for 5G and Beyond,” in IEEE Communications Surveys & Tutorials, vol. 21, No. 4, pp. 3682-3722, Fourthquarter 2019, doi: 10.1109/COMS… [cited by applicant]