IP Library Granted Patent US 12,464,358
Granted Patent B2
US 12,464,358 · App. 18/482,819 · Granted Nov 4, 2025

Global mobile communication event IDs for improved network and security operations

Inventors: Geoffrey Todd Gibson (Rowlett, TX); Marouane Balmakhtar (Fairfax, VA)
Assignee: T-Mobile USA, Inc.
H04W12/122
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,464,358
App. No.
18/482,819
Granted
Nov 4, 2025
Kind
B2
Abstract

Global mobile communication event identifiers (IDs) improve security by enabling early detection of cybersecurity events in cellular networks. The event IDs are each unique to a category of mobile communication events and consistent across the network functions (NF), even from different vendors. NFs assign event IDs to mobile communication events, which are reported to a cybersecurity operations center. The cybersecurity operations center has visibility into network-wide events and is thus able to match occurrences of event IDs with categorized attacks, when an attack is occurring. This enables rapid, intelligent selection of a defensive response.

Claims (75)

1 . A method comprising:

assigning, by a first network function (NF) of a wireless network, to a first mobile communication event, a first event identifier (ID) of a first set of event IDs, each event ID within the first set of event IDs being unique to a category of mobile communication events and consistent across NFs of the wireless network;

recording, within a first event log at the first NF, a first log entry indicating an occurrence of the first mobile communication event, the first log entry comprising the first event ID and a timestamp;

assigning, by a second NF of the wireless network, to a second mobile communication event, the first event ID, wherein the first mobile communication event and the second mobile communication event are within a common category of mobile communication events, and wherein the first NF and the second NF execute different proprietary software;

recording, within a second event log at the second NF, a second log entry indicating an occurrence of the second mobile communication event, the second log entry comprising the first event ID and a timestamp;

transmitting the first log entry and the second log entry to a cybersecurity operations center;

based on at least the first event ID and/or the second event ID, determining an occurrence of a cybersecurity event;

based on at least determining the cybersecurity event, generating an alert;

correlating a second set of event IDs with a categorized attack of a set of categorized attacks, the second set of event IDs including the first event ID and a second event ID, the second event ID different than the first event ID; and

receiving, by the cybersecurity operations center, a third log entry comprising the second event ID of the first set of event IDs, wherein determining the occurrence of the cybersecurity event comprises determining an occurrence of the categorized attack.

2 . The method of claim 1 , further comprising:

based on at least determining the occurrence of the cybersecurity event, performing a cybersecurity event response.

3 . The method of claim 1 , further comprising:

transmitting, by the first NF, to the cybersecurity operations center, the first event log; and

transmitting, by the second NF, to the cybersecurity operations center, the second event log.

4 . The method of claim 1 , further comprising:

transmitting, by the first NF, to a log server, the first event log;

transmitting, by the second NF, to the log server, the second event log;

determining, by the log server, that the first event log and the second event log each comprises the first event ID; and

based on at least determining that the first event log and the second event log each comprises the first event ID, transmitting, by the log server, to the cybersecurity operations center, the first event log and the second event log.

5 . The method of claim 1 , further comprising:

monitoring, by the first NF, for an occurrence of the first event ID, wherein the first NF transmits the first log entry based on at least detecting the occurrence of the first event ID; and

monitoring, by the second NF, for an occurrence of the first event ID, wherein the second NF transmits the second log entry based on at least detecting the occurrence of the first event ID.

6 . The method of claim 1 , further comprising:

detecting an indication of a categorized attack, wherein transmitting the first log entry and the second log entry to the cybersecurity operations center is based on at least detecting the indication of the categorized attack.

7 . A system comprising:

a processor; and

a computer-readable medium storing instructions that are operative upon execution by the processor to:

assign, by a first network function (NF) of a wireless network, to a first mobile communication event, a first event identifier (ID) of a first set of event IDs, each event ID within the first set of event IDs being unique to a category of mobile communication events and consistent across NFs of the wireless network;

record, within a first event log at the first NF, a first log entry indicating an occurrence of the first mobile communication event, the first log entry comprising the first event ID and a timestamp;

assign, by a second NF of the wireless network, to a second mobile communication event, the first event ID, wherein the first mobile communication event and the second mobile communication event are within a common category of mobile communication events, and wherein the first NF and the second NF execute different proprietary software;

record, within a second event log at the second NF, a second log entry indicating an occurrence of the second mobile communication event, the second log entry comprising the first event ID and a timestamp;

transmit the first log entry and the second log entry to a cybersecurity operations center;

based on at least the first event ID and/or the second event ID, determine an occurrence of cybersecurity event;

based on at least determining the cybersecurity event, generating an alert;

correlate a second set of event IDs with a categorized attack of a set of categorized attacks, the second set of event IDs including the first event ID and a second event ID, the second event ID different than the first event ID; and

receive, by the cybersecurity operations center, a third log entry comprising the second event ID of the first set of event IDs, wherein determining the occurrence of the cybersecurity event comprises determining an occurrence of the categorized attack.

8 . The system of claim 7 , wherein the operations are further operative to:

based on at least determining the occurrence of the cybersecurity event, perform a cybersecurity event response.

9 . The system of claim 7 , wherein the operations are further operative to:

transmit, by the first NF, to the cybersecurity operations center, the first event log; and

transmit, by the second NF, to the cybersecurity operations center, the second event log.

10 . The system of claim 7 , wherein the operations are further operative to:

transmit, by the first NF, to a log server, the first event log;

transmit, by the second NF, to the log server, the second event log;

determine, by the log server, that the first event log and the second event log each comprises the first event ID; and

based on at least determining that the first event log and the second event log each comprises the first event ID, transmit, by the log server, to the cybersecurity operations center, the first event log and the second event log.

11 . The system of claim 7 , wherein the operations are further operative to:

monitor, by the first NF, for an occurrence of the first event ID, wherein the first NF transmits the first log entry based on at least detecting the occurrence of the first event ID; and

monitor, by the second NF, for an occurrence of the first event ID, wherein the second NF transmits the second log entry based on at least detecting the occurrence of the first event ID.

12 . The system of claim 7 , wherein the operations are further operative to:

detect an indication of a categorized attack, wherein transmitting the first log entry and the second log entry to the cybersecurity operations center is based on at least detecting the indication of the categorized attack.

13 . One or more computer storage devices having computer-executable instructions stored thereon, which, upon execution by a computer, cause the computer to perform operations comprising:

assigning, by a first network function (NF) of a wireless network, to a first mobile communication event, a first event identifier (ID) of a first set of event IDs, each event ID within the first set of event IDs being unique to a category of mobile communication events and consistent across NFs of the wireless network;

recording, within a first event log at the first NF, a first log entry indicating an occurrence of the first mobile communication event, the first log entry comprising the first event ID and a timestamp;

assigning, by a second NF of the wireless network, to a second mobile communication event, the first event ID, wherein the first mobile communication event and the second mobile communication event are within a common category of mobile communication events, and wherein the first NF and the second NF execute different proprietary software;

recording, within a second event log at the second NF, a second log entry indicating an occurrence of the second mobile communication event, the second log entry comprising the first event ID and a timestamp;

transmitting the first log entry and the second log entry to a cybersecurity operations center;

based on at least the first event ID and/or the second event ID, determining an occurrence of a cybersecurity event;

based on at least determining the cybersecurity event, generating an alert;

correlating a second set of event IDs with a categorized attack of a set of categorized attacks, the second set of event IDs including the first event ID and a second event ID, the second event ID different than the first event ID; and

receiving, by the cybersecurity operations center, a third log entry comprising the second event ID of the first set of event IDs, wherein determining the occurrence of the cybersecurity event comprises determining an occurrence of the categorized attack.

14 . The one or more computer storage devices of claim 13 , wherein the operations further comprise:

based on at least determining the occurrence of the cybersecurity event, performing a cybersecurity event response.

15 . The one or more computer storage devices of claim 13 , wherein the operations further comprise:

transmitting, by the first NF, to the cybersecurity operations center, the first event log; and

transmitting, by the second NF, to the cybersecurity operations center, the second event log.

16 . The one or more computer storage devices of claim 13 , wherein the operations further comprise:

transmitting, by the first NF, to a log server, the first event log;

transmitting, by the second NF, to the log server, the second event log;

determining, by the log server, that the first event log and the second event log each comprises the first event ID; and

based on at least determining that the first event log and the second event log each comprises the first event ID, transmitting, by the log server, to the cybersecurity operations center, the first event log and the second event log.

17 . The one or more computer storage devices of claim 13 , wherein the operations further comprise:

monitoring, by the first NF, for an occurrence of the first event ID, wherein the first NF transmits the first log entry based on at least detecting the occurrence of the first event ID; and

monitoring, by the second NF, for an occurrence of the first event ID, wherein the second NF transmits the second log entry based on at least detecting the occurrence of the first event ID.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 6, 2023
From: GIBSON, GEOFFREY TODD; BALMAKHTAR, MAROUANE
To: T-MOBILE USA, INC.
Reel/Frame 065154/0059 →
Continuity (1)
Related Publication 20250119746A1 · Apr 10, 2025
References Cited (10)
US 11005860B1 · Glyer · 2021 [cited by examiner]
US 11188397B2 · Cristofi · 2021 [cited by examiner]
US 11232437B2 · Laracey · 2022 [cited by examiner]
US 11887105B2 · Laracey · 2024 [cited by examiner]
US 12003956B2 · Naujok · 2024 [cited by examiner]
US 12019782B1 · Oliver · 2024 [cited by examiner]
US 20230315884A1 · Pham · 2023 [cited by examiner]
US 20230388352A1 · Gilad · 2023 [cited by examiner]
US 20240039929A1 · Pisha · 2024 [cited by examiner]
US 20250063064A1 · Schaaf · 2025 [cited by examiner]