IP Library Granted Patent US 9,521,145
Granted Patent B2
US 9,521,145 · App. 13/326,191 · Granted Dec 13, 2016

Methods and apparatuses to provide secure communication between an untrusted wireless access network and a trusted controlled network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,521,145
App. No.
13/326,191
Granted
Dec 13, 2016
Kind
B2
Abstract

A secure communication channel between an access point (AP) device associated with a wireless network and a mobile gateway (GW) device of a packet core network is established. Data is exchanged between the wireless network and the packet core network through the secure channel. A client device (UE) is authenticated through the secure communication channel. Device identity information is received from the AP device. A session request is sent to the packet core network. An IP address for the device is received from the packet core network. The communication between the AP device and the packet core network becomes secure without need to run an IP secure protocol on the UE that saves the battery power on the UE. Establishing the fully secure communication between the UE and the packet core network while saving the UE power provides a significant advantage for the mobile technology world.

Claims (82)

1. A machine-implemented method, comprising:

coupling a user equipment (UE) to a radio access network controller of a radio access network, wherein the radio access network controller is communicably coupled to a mobile gateway (MGW) device;

establishing a secure communication channel between an access point (AP) device associated with a wireless network and the MGW device coupling the AP device with a packet core network, wherein the AP device is communicably coupled to the UE in the wireless network and wherein the MGW device is further communicably coupled to a mobile network gateway of the wireless network;

authenticating, by a mobile network operator's authentication process, the UE through the established secure communication channel between the MGW device and the AP device, while the UE is roaming in the wireless network;

generating a mapping between an Internet Protocol (IP) access identifier and a mobile subscriber identifier for the UE;

storing the mapping between an Internet Protocol (IP) access identifier and a mobile subscriber identifier for the UE at the MGW device;

provisioning an assigned IP address from the MGW device to the UE using the secure communication channel;

mapping, by the MGW device, other IP addresses to the assigned IP address; and

in response to a packet received from the AP device via the secure communication channel, transmitting by the MGW device the packet to the packet core network, wherein the packet is originated from the UE of the wireless network, wherein the MGW manages the mobility of the UE to allow the UE to securely roam between wireless networks operated by the mobile network operator and between the wireless networks and the cellular network, and wherein the assigned IP address is used for both communication with the wireless networks and the cellular network,

wherein the MGW device determines whether the UE is attempting to establish a connection with the Internet or operator services of the mobile network operator.

2. The method of claim 1 , wherein the secure communication channel is an IP secure (IPSec) tunnel established prior to authentication of the UE by the MGW device using the AP device.

3. The method of claim 1 , wherein the wireless network is a WiFi network controlled by the AP device.

4. The method of claim 1 , wherein in response to the packet received from the UE, the AP device is configured to encrypt the packet using an encryption method compatible with the secure communication channel and to transmit the encrypted packet to the MGW device via the secure communication channel.

5. The method of claim 4 , further comprising:

decrypting the encrypted packet by the MGW device; and

transmitting from the MGW device the decrypted packet to a P-GW/GGSN of the packet core network via a GTP tunnel.

6. The method of claim 5 , further comprising:

in response to a second packet received from the P-GW/GGSN of the packet core network, encrypting by the MGW device the second packet using an encryption method compatible with the secure communication channel; and

transmitting the encrypted second packet to the AP device via the secure communication channel.

7. The method of claim 6 , wherein the AP device is configured to decrypt the encrypted second packet and to transmit the second packet to the UE over the wireless network, such that the UE does not have to handle additional IPSec functionality and the UE battery life is enhanced.

8. The method of claim 1 , further comprising:

receiving by the MGW device a device identity associated with the UE encrypted by the AP device;

sending a session request to the packet core network based on the identity;

receiving a session response from the packet core network, the session response including an IP address allocated by the packet core network; and

assigning the IP address to the UE.

9. A non-transitory machine-readable storage medium storing instructions therein, which when executed by a data processing system, cause the data processing system to perform operations comprising:

coupling a user equipment (UE) to a radio access network controller of a radio access network, wherein the radio access network controller is communicably coupled to a mobile gateway (MGW) device;

establishing a secure communication channel between an access point (AP) device associated with a wireless network and the MGW device coupling the AP device with a packet core network, wherein the MGW device is further communicably coupled to a mobile network gateway of the packet core network;

wherein the AP device is communicably coupled to the UE of the wireless network;

authenticating, by a mobile network operator's authentication process, the UE through the established secure communication channel between the MGW and the AP device, while the UE is roaming in the wireless network;

generating a mapping between an Internet Protocol (IP) access identifier and a mobile subscriber identifier for the UE;

storing the mapping between an Internet Protocol (IP) access identifier and a mobile subscriber identifier for the UE at the MGW device;

provisioning an assigned IP address from the MGW device to the UE using the secure communication channel;

mapping, by the MGW device, other IP addresses to the assigned IP address; and

in response to a packet received from the AP device via the secure communication channel, transmitting by the MGW device the packet to the packet core network, wherein the packet is originated from the UE of the wireless network, wherein the MGW manages the mobility of the UE to allow the UE to securely roam between wireless networks operated by the mobile network operator, and wherein the assigned IP address is used for both communication with the wireless networks and the cellular network,

wherein the MGW device determines whether the UE is attempting to establish a connection with the Internet or operator services of the mobile network operator.

10. The non-transitory machine-readable storage medium of claim 9 , wherein the secure communication channel is an IP secure (IPSec) tunnel established prior to authentication of the UE by the MGW device using the AP device.

11. The non-transitory machine-readable storage medium of claim 9 , wherein the wireless network is a WiFi network controlled by the AP device.

12. The non-transitory machine-readable storage medium of claim 9 , wherein in response to the packet received from the UE, the AP device is configured to encrypt the packet using an encryption method compatible with the secure communication channel and to transmit the encrypted packet to the MGW device via the secure communication channel.

13. The non-transitory machine-readable storage medium of claim 12 , wherein the method further comprises:

decrypting the encrypted packet by the MGW device; and

transmitting from the MGW device the decrypted packet to a P-GW/GGSN of the packet core network via a GTP tunnel.

14. The non-transitory machine-readable storage medium of claim 13 , wherein the method further comprises:

in response to a second packet received from the P-GW/GGSN of the packet core network, encrypting by the MGW device the second packet using an encryption method compatible with the secure communication channel; and

transmitting the encrypted second packet to the AP device via the secure communication channel.

15. The non-transitory machine-readable storage medium of claim 14 , wherein the AP device is configured to decrypt the encrypted second packet and to transmit the second packet to the UE over the wireless network, such that the UE does not have to handle IPSec security functionality and the UE battery life is thereby enhanced.

16. The non-transitory machine-readable storage medium of claim 9 , wherein the method further comprises:

receiving by the MGW device a device identity associated with the UE encrypted by the AP device;

sending a session request to the packet core network based on the identity;

receiving a session response from the packet core network, the session response including an IP address allocated by the packet core network; and

assigning the IP address to the UE.

17. A network element, comprising:

a processor; and

a memory coupled to the processor for storing instructions, which when executed from the memory, causes the processor to:

couple a user equipment (UE) to a radio access network controller of a radio access network, wherein the radio access network controller is communicably coupled to a mobile gateway (MGW) device;

establish a secure communication channel with an access point (AP) device that is communicably coupled to the UE in a wireless network, wherein the MGW device is further communicably coupled to a mobile network gateway of the wireless network;

authenticate, by a mobile network operator's authentication process, the UE through the established secure communication channel between the MGW device and the AP device, while the UE is roaming in the wireless network;

generate a mapping between an Internet Protocol (IP) access identifier and a mobile subscriber identifier for the UE;

store the mapping between an Internet Protocol (IP) access identifier and a mobile subscriber identifier for the UE at the MGW device;

provision an assigned IP address from the MGW device to the UE using the secure communication channel;

map, by the MGW device, other IP addresses to the assigned IP address; and

in response to a packet received from the AP device via the secure communication channel, transmit the packet to a packet core network, wherein the packet is originated from the UE of the wireless network, wherein the MGW manages the mobility of the UE to allow the UE to securely roam between wireless networks operated by the mobile network operator, and wherein the assigned IP address is used for both communication with the wireless networks and the cellular network,

wherein the MGW device determines whether the UE is attempting to establish a connection with the Internet or operator services of the mobile network operator.

18. The network element of claim 17 , wherein the secure communication channel is an IP secure (IPSec) tunnel established prior to authentication of the UE by the MGW device using the AP device.

19. The network element of claim 17 , wherein the wireless network is a WiFi network controlled by the AP device.

20. The network element of claim 17 , wherein in response to the packet received from the UE, the AP device is configured to encrypt the packet using an encryption method compatible with the secure communication channel and to transmit the encrypted packet to the network element via the secure communication channel.

21. The network element of claim 20 , wherein the processor is further configured to:

decrypt the encrypted packet by the MGW device; and

transmit from the MGW device the decrypted packet to a P-GW/GGSN of the packet core network via a GTP tunnel.

22. The network element of claim 21 , wherein the processor is further configured to:

in response to a second packet received from the P-GW/GGSN of the packet core network, encrypt by the MGW device the second packet using an encryption method compatible with the secure communication channel; and

transmit the encrypted second packet to the AP device via the secure communication channel.

23. The network element of claim 17 , wherein the AP device is configured to:

decrypt the encrypted second packet; and

transmit the second packet to the UE over the wireless network, such that the UE does not have to handle IPSec security functionality and UE battery life is enhanced.

24. The network element of claim 17 , wherein the processor is further configured to:

receive by the MGW device a device identity associated with the UE from the AP device;

send a session request to the packet core network based on the identity;

receive a session response from the packet core network, the session response including an IP address allocated by the packet core network; and

assign the IP address to the UE.

25. The method of claim 1 , wherein the MGW device determines whether the UE is attempting to establish a communication path to the Internet or to the packet core network.

26. The method of claim 1 , wherein the MGW devices determines whether to divert data directly to the Internet.

Assignments (27)
RELEASE OF SECURITY INTEREST IN COLLATERAL RECORDED AT REEL 069113 AND FRAME 0558 Recorded Jul 31, 2025
From: GLAS USA LLC
To: MAVENIR SYSTEMS, INC.
Reel/Frame 072308/0172 →
RELEASE OF SECURITY INTEREST IN COLLATERAL RECORDED AT REEL 067565 AND FRAME 0678 Recorded Jul 29, 2025
From: WILMINGTON SAVINGS FUND SOCIETY, FSB
To: MAVENIR SYSTEMS, INC.
Reel/Frame 072263/0421 →
RELEASE OF SECURITY INTERESTS (SYNDICATED) Recorded Jul 29, 2025
From: JPMORGAN CHASE BANK, N.A.
To: MAVENIR SYSTEMS, INC.
Reel/Frame 072263/0121 →
RELEASE OF SECURITY INTERESTS (SIDECAR) Recorded Jul 29, 2025
From: JPMORGAN CHASE BANK, N.A.
To: MAVENIR SYSTEMS, INC.
Reel/Frame 072263/0041 →
GRANT OF SECURITY INTEREST - PATENTS Recorded Jul 29, 2025
From: MAVENIR NETWORKS, INC.; MAVENIR SYSTEMS, INC.; ARGYLE DATA, INC.; MAVENIR, INC.; AQUTO CORPORATION; MAVENIR IPA UK LIMITED; MAVENIR SYSTEMS UK LIMITED; MAVENIR LTD.; MAVENIR US INC.
To: GLAS USA LLC
Reel/Frame 072245/0764 →
SECURITY INTEREST Recorded Jul 28, 2025
From: MAVENIR NETWORKS, INC.; MAVENIR SYSTEMS, INC.; ARGYLE DATA, INC.; MAVENIR, INC.; AQUTO CORPORATION; MAVENIR IPA UK LIMITED; MAVENIR SYSTEMS UK LIMITED; MAVENIR LTD.; MAVENIR US INC.
To: BLUE TORCH FINANCE LLC
Reel/Frame 072268/0439 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 032409/0858 Recorded May 15, 2025
From: FIRST-CITIZENS BANK & TRUST AS SUCCESSOR IN INTEREST TO SILICON VALLEY BANK
To: MAVENIR SYSTEMS, INC. AS SUCCESSOR IN INTEREST TO STOKE, INC.
Reel/Frame 071279/0767 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 4, 2024
From: MAVENIR SYSTEMS, INC.
To: GLAS USA LLC
Reel/Frame 069113/0558 →
RELEASE OF SECURITY INTEREST Recorded Oct 4, 2024
From: WILMINGTON SAVINGS FUND SOCIETY, FSB
To: MAVENIR SYSTEMS, INC.
Reel/Frame 069113/0596 →
SECURITY INTEREST Recorded Aug 30, 2024
From: MAVENIR SYSTEMS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 068822/0966 →
SECURITY INTEREST Recorded May 29, 2024
From: MAVENIR SYSTEMS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 067565/0678 →
SECURITY AGREEMENT Recorded Jul 13, 2022
From: MAVENIR SYSTEMS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 060641/0242 →
SECURITY AGREEMENT Recorded Aug 18, 2021
From: MAVENIR SYSTEMS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 057221/0801 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL - RELEASE OF 046139.0299 Recorded Aug 18, 2021
From: GOLDMAN SACHS LENDING PARTNERS LLC, AS COLLATERAL AGENT
To: MAVENIR SYSTEMS, INC.
Reel/Frame 057222/0398 →
GRANT OF SECURITY INTEREST IN PATENTS Recorded May 14, 2018
From: MAVENIR SYSTEMS, INC.
To: GOLDMAN SACHS LENDING PARTNERS LLC, AS COLLATERAL AGENT
Reel/Frame 046139/0299 →
RELEASE OF SECURITY INTEREST Recorded May 10, 2018
From: CERBERUS BUSINESS FINANCE, LLC, AS COLLATERAL AGENT
To: MAVENIR SYSTEMS, INC. (F/K/A MITEL MOBILITY INC.)
Reel/Frame 045773/0100 →
CHANGE OF NAME Recorded Apr 21, 2017
From: MITEL MOBILITY INC.
To: MAVENIR SYSTEMS, INC.
Reel/Frame 042369/0185 →
GRANT OF A SECURITY INTEREST -- PATENTS Recorded Mar 3, 2017
From: MAVENIR SYSTEMS, INC. (F/K/A MITEL MOBILITY INC.)
To: CERBERUS BUSINESS FINANCE, LLC, AS COLLATERAL AGENT
Reel/Frame 041877/0881 →
PARTIAL RELEASE OF SECURITY INTEREST IN PATENTS Recorded Mar 2, 2017
From: BANK OF AMERICA, N.A.
To: MITEL MOBILITY INC. (F/K/A MAVENIR SYSTEMS, INC.)
Reel/Frame 041868/0256 →
SECURITY INTEREST Recorded Mar 22, 2016
From: MITEL MOBILITY INC.
To: BANK OF AMERICA, N.A., AS THE COLLATERAL AGENT
Reel/Frame 038056/0269 →
MERGER AND CHANGE OF NAME Recorded Oct 22, 2015
From: MAVENIR INTERNATIONAL HOLDINGS, INC.; MITEL MOBILITY INC.
To: MITEL MOBILITY INC.
Reel/Frame 036861/0463 →
RELEASE OF SECURITY INTEREST Recorded May 1, 2015
From: SILICON VALLEY BANK
To: MAVENIR SYSTEMS, INC.; MAVENIR HOLDINGS, INC.; MAVENIR INTERNATIONAL HOLDINGS, INC. FKA STOKE, INC.; MAVENIR SYSTEMS IP HOLDINGS, LLC
Reel/Frame 035551/0171 →
MERGER Recorded Apr 10, 2015
From: STOKE, INC.
To: MAVENIR INTERNAITONAL HOLDINGS, INC.
Reel/Frame 035381/0064 →
SECURITY AGREEMENT Recorded Nov 20, 2014
From: MAVENIR INTERNATIONAL HOLDINGS, INC. (F/K/A STOKE, INC.)
To: SILICON VALLEY BANK
Reel/Frame 034332/0640 →
SECURITY INTEREST Recorded Mar 12, 2014
From: STOKE, INC.
To: SILICON VALLEY BANK
Reel/Frame 032409/0858 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 10, 2012
From: BHATT, YOGESH; ANNALURU, SASHIDHAR; GARG, MUKESH
To: STOKE, INC.
Reel/Frame 028020/0061 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 14, 2011
From: ANNALURU, SASHIDHAR; GARG, MUKESH
To: STOKE, INC.
Reel/Frame 027391/0411 →