IP Library › Granted Patent US 12,284,158
Granted Patent B2
US 12,284,158 · App. 17/491,819 · Granted Apr 22, 2025

Cloud-based 5G security network architectures with workload isolation

Inventors: Nathan Howe (Frankfurt, DE); Kenneth B. Urquhart (Rancho Mirage, CA)
Assignee: Zscaler, Inc.
H04L63/029H04L63/0227H04L63/1425H04W28/0925H04W28/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,284,158
App. No.
17/491,819
Granted
Apr 22, 2025
Kind
B2
Abstract

Cloud-based 5G security, implemented in a Multi-Access Edge Compute (MEC) system, includes steps of receiving a request for compute resources from User Equipment (UE); validating a user of the UE for the compute resources; responsive to the user being authorized, creating a connection between the UE and a destination of the compute resources; responsive to the user being unauthorized, rendering the compute resources as hidden from the UE. The steps can include utilizing a cloud-based system for control and signaling the connection.

Claims (35)

1. A method of cloud-based 5G security, implemented in a Multi-Access Edge Compute (MEC) system, comprising:

receiving a request for compute resources from User Equipment (UE);

validating in edge transport defining a virtual switch in the MEC a user of the UE for the compute resources;

responsive to the user being authorized, creating a connection between the UE and a destination of the compute resources;

responsive to the user being unauthorized, rendering the compute resources as hidden from the UE.

2. The method of claim 1 , further comprising utilizing a cloud-based system configured to implement a zero-trust layer for edge-hosted workload control and signaling the connection.

3. The method of claim 2 , wherein the cloud-based system is connected to the MEC via an encrypted tunnel adapted to be non-reliant on underlying mobile network transports.

4. The method of claim 1 , wherein the compute resources are hosted locally at the MEC for lower latency applications.

5. The method of claim 1 , further comprising performing the validating for each substantiation of the connection.

6. The method of claim 1 , further comprising tearing down the connection at session completion.

7. A Multi-Access Edge Compute (MEC) system comprising:

one or more servers each including at least one processor and memory storing instructions that, when executed, cause the at least one processor to receive a request for compute resources from User Equipment (UE);

validate in edge transport defining a virtual switch in the MEC a user of the UE for the compute resources;

responsive to the user being authorized, create a connection between the UE and a destination of the compute resources;

responsive to the user being unauthorized, render the compute resources as hidden from the UE.

8. The MEC system of claim 7 , wherein the instructions, when executed, cause the at least one processor to

utilize a cloud-based system for control and signaling the connection.

9. The MEC system of claim 8 , wherein the cloud-based system is connected to the MEC via an encrypted tunnel.

10. The MEC system of claim 7 , wherein the compute resources are hosted locally at the MEC for lower latency applications.

11. The MEC system of claim 7 , wherein the instructions, when executed, cause the at least one processor to

perform the validate for each substantiation of the connection.

12. The MEC system of claim 7 , wherein the instructions, when executed, cause the at least one processor to

tear down the connection at session completion.

13. A non-transitory computer-readable storage medium having computer-readable code stored thereon for programming a Multi-Access Edge Compute (MEC) system to perform steps of:

receiving a request for compute resources from User Equipment (UE);

validating in edge transport defining a virtual switch in the MEC a user of the UE for the compute resources;

responsive to the user being authorized, creating a connection between the UE and a destination of the compute resources;

responsive to the user being unauthorized, rendering the compute resources as hidden from the UE.

14. The non-transitory computer-readable storage medium of claim 13 , wherein the steps further include

utilizing a cloud-based system for control and signaling the connection.

15. The non-transitory computer-readable storage medium of claim 14 , wherein the cloud-based system is connected to the MEC via an encrypted tunnel.

16. The non-transitory computer-readable storage medium of claim 13 , wherein the compute resources are hosted locally at the MEC for lower latency applications.

17. The non-transitory computer-readable storage medium of claim 13 , wherein the steps further include

performing the validating for each substantiation of the connection.

18. The method of claim 1 , further comprising directing the traffic traversing the edge transport with an intelligent steering solution defining at least one key outcome.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 1, 2021
From: HOWE, NATHAN; URQUHART, KENNETH B.
To: ZSCALER, INC.
Reel/Frame 057668/0311 →
Continuity (3)
Continuation In Part 17371408 · Jul 9, 2021
Continuation In Part 17194568 · Mar 8, 2021
Related Publication 20220286428A1 · Sep 8, 2022
References Cited (33)
US 7894350B2 · Kailash et al. · 2011 [cited by applicant]
US 8010085B2 · Apte et al. · 2011 [cited by applicant]
US 8259571B1 · Raphel et al. · 2012 [cited by applicant]
US 8458786B1 · Kailash et al. · 2013 [cited by applicant]
US 8464335B1 · Sinha et al. · 2013 [cited by applicant]
US 9350644B2 · Desai et al. · 2016 [cited by applicant]
US 9473537B2 · Sinha et al. · 2016 [cited by applicant]
US 9531758B2 · Devarajan et al. · 2016 [cited by applicant]
US 10375024B2 · Foxhoven et al. · 2019 [cited by applicant]
US 10609083B2 · Kailash et al. · 2020 [cited by applicant]
US 10728246B2 · Bansal · 2020 [cited by applicant]
US 11882000B2 · Chandrashekhar · 2024 [cited by examiner]
US 12212491B2 · Atwal · 2025 [cited by examiner]
US 20150372982A1 · Herle et al. · 2015 [cited by applicant]
US 20160012251A1 · Singh · 2016 [cited by examiner]
US 20160150350A1 · Ingale · 2016 [cited by examiner]
US 20200077265A1 · Singh et al. · 2020 [cited by applicant]
US 20200336913A1 · Pampati et al. · 2020 [cited by applicant]
US 20210117249A1 · Doshi · 2021 [cited by examiner]
US 20210160237A1 · Rozner · 2021 [cited by examiner]
US 20220247678A1 · Atwal · 2022 [cited by examiner]
US 20220385458A1 · Keith, Jr. · 2022 [cited by examiner]
US 20220393952A1 · Mortsolf · 2022 [cited by examiner]
US 20220408333A1 · Ryu · 2022 [cited by examiner]
US 20230106024A1 · Keith, Jr. · 2023 [cited by examiner]
US 20230107624A1 · Keith, Jr. · 2023 [cited by examiner]
US 20230114650A1 · Keith, Jr. · 2023 [cited by examiner]
US 20230126039A1 · Bichot · 2023 [cited by examiner]
US 20240022565A1 · Keith, Jr. · 2024 [cited by examiner]
US 20240112008A1 · Malik · 2024 [cited by examiner]
US 20240259857A1 · Zhu · 2024 [cited by examiner]
US 20240267783A1 · Howe · 2024 [cited by examiner]
US 20250031048A1 · Verma · 2025 [cited by examiner]
Cited By (1)
US 12,438,847