IP Library › Granted Patent US 12,574,734
Granted Patent B2
US 12,574,734 · App. 18/225,022 · Granted Mar 10, 2026

Selective intelligent offloading for mobile networks using a security platform

Inventors: Sachin Verma (Danville, CA); Leonid Burakovsky (Pleasanton, CA); Apoorva Jain (San Jose, CA); John Edward McDowall (Redwood City, CA)
Assignee: Palo Alto Networks, Inc.
H04W12/088H04L63/1425H04W12/72
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,574,734
App. No.
18/225,022
Filed
Jul 21, 2023
Granted
Mar 10, 2026
Kind
B2
Art Unit
2431
USPC
726/11
Abstract

Techniques for selective intelligent offloading for mobile networks using a security platform are disclosed. In some embodiments, a system/process/computer program product for selective intelligent offloading for mobile networks using a security platform monitoring network traffic in a core mobile network using a security platform executed on a network element in the core mobile network to identify a new session that attached to the core mobile network for mobile network communications; extracting meta information associated with the new session using the security platform executed on the network element in the core mobile network; applying selective intelligent offloading using the security platform if the extracted meta information associated with the new session matches a selective intelligent offload policy; and performing traffic inspection by the security platform if the extracted meta information associated with the new session does not match a selective intelligent offload policy.

Claims (39)

1 . A system, comprising:

a processor configured to:

monitor network traffic in a core mobile network using a security platform executed on a network element in the core mobile network to identify a new session that attached to the core mobile network for mobile network communications, wherein the new session includes a flow;

extract meta information associated with the new session using the security platform executed on the network element in the core mobile network, wherein the meta information includes one or more of the following: subscriber identity information, equipment identity information, location information, access point name (APN), data network name (DNN), user equipment (UE) device information, radio access technology (RAT) information, network slice information;

apply selective intelligent offloading using the security platform if the extracted meta information associated with the new session matches a selective intelligent offload policy, comprising to:

determine whether a first IP address associated with at least one packet in the flow matches a second IP address associated with a selective intelligent enforcement rule in the selective intelligent offload policy; and

in response to a determination that the first IP address matches the second IP address:

set up the new session for the flow; and

send traffic associated with the flow to the security platform to apply security; and

perform traffic inspection by the security platform if the extracted meta information associated with the new session does not match a selective intelligent offload policy; and

a memory coupled to the processor and configured to provide the processor with instructions.

2 . The system recited in claim 1 , wherein the security platform is executed on a host entity in the core mobile network.

3 . The system recited in claim 1 , wherein the security platform is a virtual firewall executed on a host entity in the core mobile network.

4 . The system recited in claim 1 , wherein the offloading of the new session to bypass inspection by the security platform if the extracted meta information associated with the new session matches the selective intelligent offload policy is performed by offloading the new session to a smart network interface card (NIC) of the network element.

5 . The system recited in claim 1 , wherein the offloading of the new session to bypass inspection by the security platform if the extracted meta information associated with the new session matches the selective intelligent offload policy is performed by offloading the new session to a smart network interface card (NIC) of the network element, and wherein the smart NIC includes a data processing unit.

6 . The system recited in claim 1 , wherein the security platform is configured with a plurality of security policies to apply network slice based security, subscriber identity based security, equipment identity based security, access point name (APN) based security, data network name (DNN) based security, location based security, and/or radio access technology (RAT) based security in the core mobile network.

7 . The system recited in claim 1 , wherein the processor is further configured to:

extract the meta information associated with the new session using the security platform executed on the network element in the core mobile network by performing inspection of packet forwarding control protocol (PFCP) messages, application programming interfaces (APIs), and/or syslog messages.

8 . A method, comprising:

monitoring network traffic in a core mobile network using a security platform executed on a network element in the core mobile network to identify a new session that attached to the core mobile network for mobile network communications, wherein the new session includes a flow;

extracting meta information associated with the new session using the security platform executed on the network element in the core mobile network, wherein the meta information includes one or more of the following: subscriber identity information, equipment identity information, location information, access point name (APN), data network name (DNN), user equipment (UE) device information, radio access technology (RAT) information, network slice information;

applying apply selective intelligent offloading using the security platform if the extracted meta information associated with the new session matches a selective intelligent offload policy, comprising:

determining whether a first IP address associated with at least one packet in the flow matches a second IP address associated with a selective intelligent enforcement rule in the selective intelligent offload policy; and

in response to a determination that the first IP address matches the second IP address:

setting up the new session for the flow; and

sending traffic associated with the flow to the security platform to apply security; and

performing traffic inspection by the security platform if the extracted meta information associated with the new session does not match a selective intelligent offload policy.

9 . The method of claim 8 , wherein the security platform is executed on a host entity in the core mobile network.

10 . The method of claim 8 , wherein the security platform is a virtual firewall executed on a host entity in the core mobile network.

11 . The method of claim 8 , wherein the offloading of the new session to bypass inspection by the security platform if the extracted meta information associated with the new session matches the selective intelligent offload policy is performed by offloading the new session to a smart network interface card (NIC) of the network element.

12 . A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

monitoring network traffic in a core mobile network using a security platform executed on a network element in the core mobile network to identify a new session that attached to the core mobile network for mobile network communications, wherein the new session includes a flow;

extracting meta information associated with the new session using the security platform executed on the network element in the core mobile network, wherein the meta information includes one or more of the following: subscriber identity information, equipment identity information, location information, access point name (APN), data network name (DNN), user equipment (UE) device information, radio access technology (RAT) information, network slice information;

applying apply selective intelligent offloading using the security platform if the extracted meta information associated with the new session matches a selective intelligent offload policy, comprising:

determining whether a first IP address associated with at least one packet in the flow matches a second IP address associated with a selective intelligent enforcement rule in the selective intelligent offload policy; and

in response to a determination that the first IP address matches the second IP address:

setting up the new session for the flow; and

sending traffic associated with the flow to the security platform to apply security; and

performing traffic inspection by the security platform if the extracted meta information associated with the new session does not match a selective intelligent offload policy.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 4, 2023
From: VERMA, SACHIN; BURAKOVSKY, LEONID; JAIN, APOORVA; MCDOWALL, JOHN EDWARD
To: PALO ALTO NETWORKS, INC.
Reel/Frame 065122/0252 →
Continuity (1)
Related Publication 20250031043A1 · Jan 23, 2025
References Cited (102)
US 8612612B1 · Dukes · 2013 [cited by applicant]
US 9203860B1 · Casillas · 2015 [cited by applicant]
US 10374871B2 · Ramachandran · 2019 [cited by applicant]
US 10574670B1 · Verma · 2020 [cited by applicant]
US 10771506B1 · Kumar · 2020 [cited by applicant]
US 10805292B2 · Ashok · 2020 [cited by applicant]
US 10812971B2 · Verma · 2020 [cited by applicant]
US 11012475B2 · Patnala · 2021 [cited by examiner]
US 11115799B1 · Du · 2021 [cited by applicant]
US 11140455B1 · Woodruff · 2021 [cited by applicant]
US 11283767B2 · Verma · 2022 [cited by applicant]
US 11411967B2 · Valluri · 2022 [cited by examiner]
US 11520792B2 · Zhang · 2022 [cited by applicant]
US 11552975B1 · Zhang · 2023 [cited by applicant]
US 11665139B2 · Mcdowall · 2023 [cited by applicant]
US 11689502B2 · Burakovsky · 2023 [cited by examiner]
US 11696095B2 · Edge · 2023 [cited by applicant]
US 11751045B2 · Tamura · 2023 [cited by applicant]
US 11929987B1 · D N · 2024 [cited by applicant]
US 11950144B2 · Verma · 2024 [cited by examiner]
US 11979746B1 · Verma · 2024 [cited by examiner]
US 11985584B2 · Tiwari · 2024 [cited by applicant]
US 12002117B1 · Paczkowski · 2024 [cited by examiner]
US 12021789B2 · Barac · 2024 [cited by examiner]
US 12028316B2 · Wang · 2024 [cited by applicant]
US 12244647B2 · Verma · 2025 [cited by examiner]
US 12284192B2 · Malhotra · 2025 [cited by examiner]
US 12301600B2 · Tian · 2025 [cited by applicant]
US 12302451B2 · Siddam · 2025 [cited by applicant]
US 20040193943A1 · Angelino · 2004 [cited by applicant]
US 20130070596A1 · Yeh · 2013 [cited by applicant]
US 20140122435A1 · Chavda · 2014 [cited by applicant]
US 20160149863A1 · Walker · 2016 [cited by applicant]
US 20160269371A1 · Coimbatore · 2016 [cited by applicant]
US 20160342801A1 · Sreekanti · 2016 [cited by applicant]
US 20170250953A1 · Jain · 2017 [cited by applicant]
US 20180063195A1 · Nimmagadda · 2018 [cited by applicant]
US 20190012162A1 · Vaikar · 2019 [cited by applicant]
US 20190053308A1 · Castellanos Zamora · 2019 [cited by examiner]
US 20190068641A1 · Araujo · 2019 [cited by applicant]
US 20190253389A1 · Verma · 2019 [cited by applicant]
US 20190394170A1 · Shameli-Sendi · 2019 [cited by applicant]
US 20200059992A1 · Skog · 2020 [cited by applicant]
US 20200128399A1 · Verma · 2020 [cited by examiner]
US 20200274852A1 · Ahmed · 2020 [cited by applicant]
US 20200396164A1 · Arimanda · 2020 [cited by applicant]
US 20200412755A1 · Jing · 2020 [cited by applicant]
US 20210127271A1 · Wu · 2021 [cited by applicant]
US 20210271777A1 · Netsch · 2021 [cited by applicant]
US 20220159067A1 · Wang · 2022 [cited by applicant]
US 20220224706A1 · Peng · 2022 [cited by applicant]
US 20220353240A1 · Mcdowall · 2022 [cited by applicant]
US 20230095870A1 · Du · 2023 [cited by applicant]
US 20230188551A1 · Woodworth · 2023 [cited by applicant]
US 20230224704A1 · Atarius · 2023 [cited by applicant]
US 20230259614A1 · Gechman · 2023 [cited by examiner]
US 20230262076A1 · Gechman · 2023 [cited by applicant]
US 20230276228A1 · Verma · 2023 [cited by applicant]
US 20240007494A1 · Mrozinski · 2024 [cited by examiner]
US 20240056803A1 · Huang · 2024 [cited by examiner]
US 20240073698A1 · Verma · 2024 [cited by applicant]
US 20240146702A1 · Puente Pestaña · 2024 [cited by examiner]
US 20240406755A1 · Potluri · 2024 [cited by examiner]
US 20240430680A1 · Rappard · 2024 [cited by examiner]
US 20250080423A1 · Kumar · 2025 [cited by examiner]
US 20250193824A1 · Tiwari · 2025 [cited by applicant]
CN 107959614 · 2020 [cited by applicant]
EP 2933963 · 2018 [cited by applicant]
WO 2003025766 · 2003 [cited by applicant]
WO 2020198157 · 2020 [cited by applicant]
Ivanov Konstantin, Containerization with LXC, Feb. 1, 2017. [cited by applicant]
Nam et al., Bastion: A Security Enforcement Network Stack for Container Networks, USENIX, The Advanced Computing Systems Association, Feb. 3, 2021, pp. 1-24. [cited by applicant]
Author Unknown, Generic Flow API (rte_flow)—Data Plane Development Kit 21.05.0-rc1 documentation, downloaded Apr. 22, 2021. [cited by applicant]
ETSI, ETSI GS MEC 013 V3.1.1 (Jan. 2023), Group Specification, Multi-access Edge Computing (MEC); Location API. [cited by applicant]
ETSI, ETSI TS 129 571 V16.6.0 (Jan. 2021), Technical Specification, 5G; 5G System; Common Data Types for Service Based Interfaces; Stage 3, (3GPP TS 29.571 version 16.6.0 Release 16). [cited by applicant]
ETSI, ETSI TS 129 572 V16.6.0 (Apr. 2021), Technical Specification, 5G; 5G System; Location Management Services; Stage 3 (3GPP TS 29.572 version 16.6.0 Release 16). [cited by applicant]
Github, cni/SPEC.md at Master, containernetworking/cni, Container Network Interface (CNI) Specification, downloaded May 18, 2021. [cited by applicant]
Github, sessionOffload/GeneveOpenOffload.md at master—att/sessionOffload, downloaded Apr. 21, 2021. [cited by applicant]
Github, sessionOffload/openoffload.proto at v1beta1—att/sessionOffload, Apr. 30, 2021. [cited by applicant]
Gross et al., RFC 8926—Geneve: Generic Network Virtualization Encapsulation, Internet Engineering Task Force (IETF), Nov. 2020. [cited by applicant]
Istio, Istio Security, downloaded May 18, 2021. [cited by applicant]
Kubernetes, Network Plugins, downloaded May 18, 2021. [cited by applicant]
Mallu et al., Maintaining Transport Layer Security All the Way to Your Container: Using the Application Load Balancer with Amazon ECS and Envoy, May 29, 2020, pp. 1-22. [cited by applicant]
Nvidia, Nvidia Mellanox Bluefield-2, Data Processing Unit (DPU), Product Brief, Aug. 2020. [cited by applicant]
Palo Alto Networks, APP-ID, Technology Brief, pp. 1-5, downloaded Apr. 21, 2021. [cited by applicant]
Park et al., Core Container Security Frameworks, International Journal of Advanced Research in Engineering and Technology (IJARET), vol. 11, Issue 6, Jun. 2020, pp. 1024-1038. [cited by applicant]
Thaler et al., Making eBPF Work on Windows, Microsoft Open Source Blog, (https://cloudblogs.microsoft.com/opensource/), May 10, 2021. [cited by applicant]
Wikipedia, Bump-in-the-Wire, page last edited Sep. 7, 2020. [cited by applicant]
3GPP, 3GPP TR 33.811 V15.0.0 (Jun. 2018), 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on security aspects of 5G network slicing management, (Release 15), 19 pages. [cited by applicant]
3GPP, 3GPP TS 23.503 V18.2.0 (Jun. 2023), 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Policy and charging control framework for the 5G System (5GS); Stage 2, (Release 1… [cited by applicant]
Author Unknown, N4 Interface Configuration, Feb. 2020, pp. 1-4. [cited by applicant]
ETSI, ETSI GS MEC 013 V3.1.1 (Jan. 2023), Group Specification, Multi-access Edge Computing (MEC); Location API, 85 pages. [cited by applicant]
ETSI, ETSI TS 129 244 V16.5.0 (Nov. 2020), Technical Specification, LTE; 5G; Interface between the Control Plane and the User Plane nodes (3GPP TS 29.244 version 16.5.0 Release 16), 317 pages. [cited by applicant]
ETSI, ETSI TS 129 281 V15.4.0 (Sep. 2018), Technical Specification, Universal Mobile Telecommunications System (UMTS); LTE; General Packet Radio System (GPRS), Tunnelling Protocol User Plane (GTPv1-U), (3GPP TS 29.281 v… [cited by applicant]
ETSI, ETSI TS 129 571 V16.6.0 (Jan. 2021), Technical Specification, 5G; 5G System; Common Data Types for Service Based Interfaces; Stage 3 (3GPP TS 29.571 version 16.6.0 Release 16), 131 pages. [cited by applicant]
ETSI, ETSI TS 129 572 V16.6.0 (Apr. 2021), Technical Specification, 5G; 5G System; Location Management Services; Stage 3 (3GPP TS 29.572 version 16.6.0 Release 16), 94 pages. [cited by applicant]
Intel, Intel® FPGA SmartNIC N6000-PL Platform, Jun. 19, 2025, 3 pages. [cited by applicant]
Liia Sarjakoski, The Four 5G Edge Environments and How to Secure Them, Dec. 16, 2021, 5 pages. [cited by applicant]
Najjar et al., WIA Innovation & Technology Council, The 5G Paradox, The Need for More Offloading Options in the Next-Generation Wireless Era, Feb. 8, 2019, 19 pages. [cited by applicant]
Nvidia, Bluefield-3 DPU, Programmable Data Center Infrastructure On-A-Chip, 2021, 2 pages. [cited by applicant]
Sabina Anja, VMware Cloud Foundation (VCE) Blog, Feb. 20, 2023, pp. 1-6. [cited by applicant]
Teppo et al., Security in 5G RAN and core deployments, Jun. 19, 2025, pp. 1-10. [cited by applicant]