IP Library Granted Patent US 12,369,014
Granted Patent B2
US 12,369,014 · App. 18/161,535 · Granted Jul 22, 2025

Wireless network policy manager for a service mesh

Inventors: David Taft (Keller, TX); Vinod Kumar Choyi (Conshohocken, PA); Maqbool Chauhan (Keller, TX); Jerry Steben (Fort Worth, TX); Parry Cornell Booker (Arlington, TX); Hossein M. Ahmadi (Parsippany, NJ); Minbao Li (Lewisville, TX); Sudhakar Reddy Patil (Flower Mound, TX)
Assignee: Verizon Patent and Licensing Inc.
H04W4/20H04L63/14H04L67/56H04W12/37H04W84/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,369,014
App. No.
18/161,535
Granted
Jul 22, 2025
Kind
B2
Abstract

A computer device may include a memory storing instructions and processor configured to execute the instructions to host a network function container that implements a microservice for a network function in a wireless communications network, wherein the network function container is deployed by a container orchestration platform; host a service proxy container associated with the network function container, wherein the service proxy container is deployed by the container orchestration platform; and configure the hosted service proxy container to apply a wireless network policy to the microservice for the network function. The processor may be further configured to intercept messages associated with the microservice for the network function using the configured service proxy container; and apply the wireless network policy to the intercepted messages using the configured service proxy container.

Claims (53)

1. A method comprising:

collecting, by a computer device, values for a plurality of metrics from a plurality of service meshes, wherein a service mesh, of the plurality of service meshes, enables communication between network function containers;

detecting, by the computer device, a security threat based on the collected values;

updating, by the computer device, a security policy based on the detected security threat; and

instructing, by the computer device, at least one of the plurality of service meshes to apply the updated security policy to network functions associated with the at least one of the plurality of service meshes.

2. The method of claim 1 , wherein detecting the security threat based on the collected values includes:

using a machine learning model trained to detect security threats in a wireless communications network.

3. The method of claim 1 , wherein different ones of the plurality of service meshes are located in different geographic locations.

4. The method of claim 1 , wherein different ones of the plurality of service meshes are associated with different providers of wireless communications networks.

5. The method of claim 1 , wherein different ones of the plurality of service meshes are associated with different enterprises.

6. The method of claim 1 , wherein different ones of the plurality of service meshes are associated with different network slices.

7. The method of claim 1 , wherein updating the security policy based on the detected security threat includes:

updating a security policy manager in a service proxy container associated with a network function container serviced by a service mesh of the plurality of service meshes.

8. The method of claim 1 , wherein updating the security policy based on the detected security threat includes:

updating a malware detection and mitigation engine associated with a service mesh of the plurality of service meshes.

9. The method of claim 1 , wherein updating the security policy based on the detected security threat includes:

updating a chain of trust detection policy,

updating a policy for flagging anomalous behavior,

updating a blacklist security policy, or

updating an encryption policy.

10. The method of claim 1 , further comprising:

load balancing traffic between different ones of the plurality of service meshes.

11. A device comprising:

a memory and;

a processor configured to execute instructions to:

collect values for a plurality of metrics from a plurality of service meshes, wherein a service mesh, of the plurality of service meshes, enables communication between network function containers;

detect a security threat based on the collected values;

update a security policy based on the detected security threat; and

instruct at least one of the plurality of service meshes to apply the updated security policy to network functions associated with the at least one of the plurality of service meshes.

12. The device of claim 11 , wherein, when detecting the security threat based on the collected values, the processor is further configured to:

use a machine learning model trained to detect security threats in a wireless communications network.

13. The device of claim 11 , wherein different ones of the plurality of service meshes are located in different geographic locations.

14. The device of claim 11 , wherein different ones of the plurality of service meshes are associated with different providers of wireless communications networks.

15. The device of claim 11 , wherein different ones of the plurality of service meshes are associated with different enterprises.

16. The device of claim 11 , wherein different ones of the plurality of service meshes are associated with different network slices.

17. The device of claim 11 , wherein, when updating the security policy based on the detected security threat, the processor is further configured to:

update a security policy manager in a service proxy container associated with a network function container serviced by a service mesh of the plurality of service meshes.

18. The device of claim 11 , wherein, when updating the security policy based on the detected security threat, the processor is further configured to:

update a malware detection and mitigation engine associated with a service mesh of the plurality of service meshes.

19. The device of claim 11 , wherein, when updating the security policy based on the detected security threat, the processor is further configured to:

update a chain of trust detection policy,

update a policy for flagging anomalous behavior,

update a blacklist security policy, or

update an encryption policy.

20. A system comprising:

a first computer device, included in a network, configured to:

implement a network function container that implements a microservice for a network function in a wireless communications network, wherein the network function container is deployed by a container orchestration platform; and

implement a service proxy container associated with the network function container, wherein the service proxy container is deployed by the container orchestration platform; and

a second computer device, included in the network, configured to:

collect values for a plurality of metrics from a plurality of service meshes, wherein a service mesh, of the plurality of service meshes, enables communication between network function containers deployed by the container orchestration platform;

detect a security threat based on the collected values;

update a security policy based on the detected security threat; and

instruct the service proxy container to apply the updated security policy to the network function container.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 30, 2023
From: TAFT, DAVID; CHOYI, VINOD KUMAR; CHAUHAN, MAQBOOL; STEBEN, JERRY; BOOKER, PARRY CORNELL; AHMADI, HOSSEIN M.; LI, MINBAO; PATIL, SUDHAKAR REDDY
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 062534/0814 →
Continuity (2)
Continuation 16899150 · Jun 11, 2020
Related Publication 20230179967A1 · Jun 8, 2023
References Cited (7)
US 11271699B1 · Eyuboglu · 2022 [cited by examiner]
US 20200358802A1 · Viswambharan · 2020 [cited by examiner]
US 20200366697A1 · Vittal · 2020 [cited by applicant]
US 20210135983A1 · Farnham · 2021 [cited by examiner]
US 20210240540A1 · Wang · 2021 [cited by examiner]
US 20220060894A1 · Pazhyannur · 2022 [cited by examiner]
“Security”, Istio 1.6: Accessed online Jun. 11, 2020 https://istio.io/latest/docs/concepts/security/. 24 pages. [cited by applicant]