IP Library Granted Patent US 12,489,788
Granted Patent B1
US 12,489,788 · App. 17/328,252 · Granted Dec 2, 2025

Programmable networking device for user plane function with internet protocol security (IPsec)

Inventor: Brian Waters (Angel Fire, NM)
Assignee: T-MOBILE INNOVATIONS LLC
H04L63/164H04L12/4641H04L63/0272H04L63/029H04L67/14H04W12/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,489,788
App. No.
17/328,252
Granted
Dec 2, 2025
Kind
B1
Abstract

Programmable network devices configured to perform various packet processing functions are further configured to use IPsec to secure control and data packets associated with data sessions traversing the UPF. Field-programmable gate arrays (FPGAs) and/or graphics processing units (GPUs) coupled with network interfaces are configured to perform user plane functions and secure data packet within a compact and modular hardware unit to minimize excessive communication while maintaining control and user plane separation (CUPS).

Claims (32)

1 . A method, comprising:

configuring an embedded hardware device to perform a plurality of user plane functions on data packets routed through the embedded hardware device, wherein configuring the embedded hardware device comprises:

communicatively coupling the embedded hardware device with a plurality of host instances, wherein each host instance is associated with a corresponding network slice; and

activating a predefined rule stored in the embedded hardware device for a network slice associated with a host instance and a data session that includes the data packets without associating the network slice with the embedded hardware device; and

securing the data packets that directly egress from a user plane of a radio access network (RAN) to a destination network using a secure virtual private networking (VPN) protocol.

2 . The method of claim 1 , further comprising determining that the data packets are associated with one or more specific interfaces as a condition to securing the data packets using IPsec.

3 . The method of claim 2 , wherein the one or more specific interfaces include one or more of an N3 interface, an N6 interface, or an N9 interface.

4 . The method of claim 3 , wherein the data packets are associated with data sessions transmitted to or from one or more of the RAN, a packet data network (PDN), or a second embedded hardware device.

5 . The method of claim 4 , wherein the embedded hardware device is communicatively coupled to a plurality of access nodes using the N3 interface.

6 . The method of claim 2 , wherein the one or more specific interfaces include an N4 interface, and the data packets are associated with control data transmitted to or from a session management function (SMF).

7 . The method of claim 1 , wherein each host instance is assigned a unique internet protocol (IP) address.

8 . The method of claim 7 , wherein securing the data packets comprises encapsulating the data packets in an IPsec tunnel associated with the unique IP address for each host.

9 . The method of claim 1 , wherein the embedded hardware device comprises at least one of a field-programmable gate array (FPGA) or a graphics processing unit (GPU).

10 . The method of claim 1 , wherein the secure VPN utilizes internet protocol security (IPsec).

11 . The method of claim 1 , further comprising storing predefined rules for each network slice associated with a corresponding host instance at the embedded hardware device.

12 . A programmable networking device, comprising:

a processor;

a memory coupled to the processor, the memory being configured to store a host module; and

an embedded hardware device coupled to the memory, the embedded hardware device configured to perform operations comprising:

performing a plurality of user plane functions on data packets routed through the embedded hardware device;

communicatively coupling the embedded hardware device with a plurality of host instances, wherein each host instance is associated with a corresponding network slice;

activating a predefined rule stored in the embedded hardware device for a network slice associated with a host instance and a data session that includes the data packets without associating the network slice with the embedded hardware device;

securing the data packets that directly egress from a user plane of a radio access network (RAN) to a destination network using internet protocol security (IPsec); and

transmitting the data packets to the host module.

13 . The programmable networking device of claim 12 , wherein the operations further comprise determining that the data packets are associated with one or more specific interfaces as a condition to securing the data packets using IPsec.

14 . The programmable networking device of claim 13 , wherein the one or more specific interfaces include one or more of an N3 interface, an N6 interface, or an N9 interface.

15 . The programmable networking device of claim 14 , wherein the data packets are associated with data sessions transmitted to or from one or more of the RAN, a packet data network (PDN), or a second FPGA.

16 . The programmable networking device of claim 15 , wherein the programmable networking device is communicatively coupled to a plurality of access nodes using the N3 interface.

17 . The programmable networking device of claim 13 , wherein the one or more specific interfaces include an N4 interface, and the data packets are associated with control data transmitted to or from a session management function (SMF).

18 . The programmable networking device of claim 12 , wherein each host instance being assigned a unique internet protocol (IP) address.

19 . The programmable networking device of claim 12 , wherein each host instance is coupled to one or more session management functions (SMFs) via an N4 interface.

20 . The programmable networking device of claim 12 , wherein the embedded hardware device comprises at least one of a field-programmable gate array (FPGA) or a graphics processing unit (GPU).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 24, 2021
From: WATERS, BRIAN
To: T-MOBILE INNOVATIONS LLC
Reel/Frame 056350/0841 →
References Cited (33)
US 7698455B2 · Jalan · 2010 [cited by examiner]
US 8165152B2 · Sammour et al. · 2012 [cited by applicant]
US 8223758B2 · Eriksson · 2012 [cited by applicant]
US 8243732B2 · Chen · 2012 [cited by examiner]
US 8259571B1 · Raphel · 2012 [cited by examiner]
US 8837285B2 · Sammour et al. · 2014 [cited by applicant]
US 10958620B1 · Wei · 2021 [cited by examiner]
US 11240206B2 · Chen · 2022 [cited by examiner]
US 20060236388A1 · Ying · 2006 [cited by examiner]
US 20070195794A1 · Fujita · 2007 [cited by examiner]
US 20070271606A1 · Amann · 2007 [cited by examiner]
US 20080186965A1 · Zheng · 2008 [cited by examiner]
US 20150365790A1 · Edge · 2015 [cited by examiner]
US 20160135096A1 · Poruri · 2016 [cited by examiner]
US 20170223523A1 · Keller · 2017 [cited by examiner]
US 20180048622A1 · Gaitatzis · 2018 [cited by examiner]
US 20190068520A1 · Kim · 2019 [cited by examiner]
US 20190069182A1 · John · 2019 [cited by examiner]
US 20190173841A1 · Wang · 2019 [cited by examiner]
US 20190182875A1 · Talebi Fard · 2019 [cited by examiner]
US 20190335002A1 · Bogineni · 2019 [cited by examiner]
US 20200245381A1 · Talebi Fard · 2020 [cited by examiner]
US 20200259807A1 · Rastogi · 2020 [cited by examiner]
US 20200280511A1 · Gapin · 2020 [cited by examiner]
US 20200404069A1 · Li · 2020 [cited by examiner]
US 20210136633A1 · Zetterlund · 2021 [cited by examiner]
US 20220045989A1 · Chen · 2022 [cited by examiner]
US 20220053401A1 · Foti · 2022 [cited by examiner]
US 20220183088A1 · Huang · 2022 [cited by examiner]
US 20240155452A1 · Salmela · 2024 [cited by examiner]
EP 3442167A1 · 2019 [cited by examiner]
WO 2019238252A1 · 2019 [cited by applicant]
Jesus Sanchez-Gomez, Integrating LPWAN Technologies in the 5G Ecosystem: A Survey on Security Challenges and Solutions, IEEE 2020. [cited by examiner]