Multi-access management service packet classification and prioritization techniques
US-12184554-B2 · Dec 31, 2024 · US
US2025080502A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2025080502-A1 |
| Application number | US-202218024336-A |
| Country | US |
| Kind code | A1 |
| Filing date | Dec 14, 2022 |
| Priority date | Dec 14, 2022 |
| Publication date | Mar 6, 2025 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A base station for securing network traffic using Internet Protocol Security (IPSec) tunnels in a telecommunication network is disclosed. The base station includes a transport manager container that handles network traffic terminations of network interfaces. The base station further includes an internet protocol (IP) security tunnel management container that exchanges one or more IKE parameters between a source IKE daemon unit deployed at the at least one POD and a destination IKE daemon unit deployed at the peer node. Further, the IP security tunnel management container (a) authenticates the peer node based on the extracted IKE parameters, (b) configure the source IKE daemon unit based on the extracted one or more IKE parameters upon successful authentication of the peer node, and (c) create at least one IP security tunnel between the at least one POD and the peer node, based on the updated security data tables in a network kernel.
Opening claim text (preview).
What is claimed is: 1 . A base station for securing network traffic using Internet Protocol Security (IPSec) tunnels in a telecommunication network, the base station comprising: one or more hardware processors; and a memory coupled to the one or more hardware processors, wherein the memory comprises a plurality of Programmable, Open, and Disaggregated Solution (POD) subsystems in a form of microservice based containers executable by the one or more hardware processors, wherein each of the plurality of POD subsystems comprises: a transport manager container configured to handle network traffic terminations of one or more network interfaces, wherein the one or more network interfaces comprises at least one of: a control path interface and data path interface; and an internet protocol (IP) security tunnel management container communicatively coupled to the transport manager container, wherein the IP security tunnel management container is configured to: receive Internet Key Exchange (IKE) day−1 local configuration for each transport manager container in each of the plurality of POD subsystems; negotiate IPsec policies with a peer node over an ISAKMP protocol according to the received IKE day−1 local configuration; receive one or more network packets from the peer node via the one or more network interfaces, wherein the peer node is communicatively connected to at least one POD subsystem of the plurality of POD subsystems of the base station; extract one or more IKE parameters for a predefined configuration time interval from the received one or more network packets, wherein the one or more IKE parameters are exchanged between a source IKE daemon unit deployed at the at least one POD and a destination IKE daemon unit deployed at the peer node; authenticate the peer node based on the extracted one or more IKE parameters; configure the source IKE daemon unit based on the extracted one or more IKE parameters upon successful authentication of the peer node; update one or more security data tables in a network kernel with a set of information upon configuring the source IKE daemon unit, wherein the set of information comprises at least one of: information associated with ciphering algorithms, one or more secret keys, one or more security policies, and information on security parameter indexes (SPI); create at least one IP security tunnel between the at least one POD and the peer node, based on the updated one or more security data tables in the network kernel; and perform one or more secure operations through the created at least one IP security tunnel, wherein the one or more secure operations comprises at least one of: an encryption and a decryption of the received one or more network packets. 2 . The base station of claim 1 , wherein the IP security tunnel management container is further configured to: monitor the created at least one IP security tunnel to determine one or more states of the created at least one IP security tunnel; and auto-restore the created at least one IP security tunnel based on the determined one or more states. 3 . The base station of claim 2 , wherein the IP security tunnel management container is further configured to: generate one or more alarm events corresponding to one or more northbound entities based on the determined one or more states. 4 . The base station of claim 1 , wherein the transport manager container and the IP security tunnel management container are deployed in a user plane of the base station. 5 . The base station of claim 1 , wherein the one or more IKE parameters comprise an IP address of the peer node, one or more ciphering algorithms, security policy details, and a peer node certificate identifier. 6 . The base station of claim 4 , further comprising a fast path terminating unit configured to register information related to security association database (SAD) and security policy database (SPD) from the network kernel using a network link socket, wherein the information related to the SAD and SPD are updated by the source IKE daemon unit when the at least one IP security tunnel is created based on one or more internet key exchange (IKE) messages exchanged with the destination IKE daemon unit. 7 . The base station of claim 1 , wherein the IP security tunnel management container is further configured to perform at least one of: enabling and disabling of the created at least one IP security tunnel based on type of network interfaces. 8 . The base station of claim 1 , wherein in authenticating the peer node based on the extracted one or more IKE parameters, the IP security tunnel management container is configured to: retrieve device certificate information of the peer node from the extracted IKE parameters; and authenticate the peer node based on the retrieved device certificate information. 9 . The base station of claim 1 , wherein the IP security tunnel management container is configured to: interact with one or more peer subsystems deployed across plurality of peer nodes for securing the network traffic within the telecommunication network. 10 . The base station of claim 1 , further comprising: a Centralized Unit Control Plane (CU-CP); a Centralized Unit User Plane (CU-UP) communicatively coupled to the CU-CP; and a Distributed Unit (DU) communicatively coupled to the CU-CP and the CU-UP, wherein each of the CU-CP, the CU-UP, and the DU comprises the plurality of POD subsystems. 11 . A method for securing network traffic using Internet Protocol Security (IPSec) tunnels in a telecommunication network, the method comprising: receiving, by a processor, an Internet Key Exchange (IKE) day−1 local configuration for a transport manager container in each of a plurality of Programmable, Open, and Disaggregated Solution (POD) subsystems of a base station; negotiating, by the processor, internet security (IPsec) policies between at least one POD of the plurality of POD subsystems and a peer node over an ISAKMP protocol according to the received IKE day−1 local configuration; receiving, by the processor, one or more network packets from the peer node via one or more network interfaces, wherein the peer node is communicatively connected to at least one POD subsystem of the plurality of POD subsystems of the base station; extracting, by the processor, one or more internet key exchange (IKE) parameters for a predefined configuration time interval from the received one or more network packets, wherein the one or more IKE parameters are exchanged between a source IKE daemon unit deployed at the base station and a destination IKE daemon unit deployed at the peer node; authenticating, by the processor, the peer node based on the extracted one or more IKE parameters; configuring, by the processor, the source IKE daemon unit based on the extracted one or more IKE parameters upon successful authentication of the peer node; updating, by the processor, one or more security data tables in a network kernel with a set of information upon configuring the source IKE daemon unit, wherein the set of information comprises at least one of: information associated with ciphering algorithms, one or more secret keys, one or more security policies, and information on a security parameter indexes (SPI); creating, by the processor, at least one IP security tunnel between the at least one POD subsystem and the peer node, based on the updated one or more security data tables in the network kernel; and performing, by the processor, one or more secure operations through the created at least one IP security tunnel, wherein the one or more secure operations comprises at least one of: an encryption and a decryption of the received one or more ne
Access point devices · CPC title
Interfaces between hierarchically similar devices · CPC title
Integrity · CPC title
using certificates or pre-shared keys · CPC title
without using a trusted network node as an anchor · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.