NRF SCP Automatic Platform Firewall Rule Synchronization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Configuring and maintaining platform firewalls in 5G telecommunications networks is labor-intensive and prone to errors, particularly in synchronizing firewall rules with changes in Network Function (NF) profiles.
Innovation Solution
A method and system for automatically managing platform firewalls using a Network Function Repository Function (NRF) or Service Communication Proxy (SCP), which receives messages related to NF profile registrations, updates, or deregistrations and automatically updates the firewall rules configuration accordingly.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual configuration of platform firewall rules is used, then configuration simplicity is maintained, but labor intensity increases and errors occur
Solution Approach 1:
The system enables automatic self-configuration of firewall rules by the NRF/SCP based on NF profile changes. The NRF/SCP automatically determines when firewall rule updates are needed and performs the configuration without manual intervention, allowing the system to serve itself rather than requiring operator manual configuration for each topology change.
Solution Approach 2:
The system establishes a feedback mechanism where the NRF/SCP continuously monitors NF profile changes and automatically triggers firewall rule updates in response. This closed-loop feedback ensures that firewall configuration automatically adapts to network topology changes, eliminating the need for manual reconfiguration and reducing errors.
2Reliability
If manual synchronization of firewall rules with NF profiles is performed, then control over configuration is maintained, but time consumption increases
Solution Approach 1:
The system implements continuous automatic synchronization between NF profiles and firewall rules. The NRF/SCP continuously monitors for profile changes and maintains ongoing updates to firewall rules, ensuring that the configuration remains current without interruption. This eliminates the periodic manual synchronization process that causes time loss and potential inaccuracies.
Solution Approach 2:
The system performs preliminary determination of whether firewall rule changes are needed before actually updating the rules. The NRF/SCP evaluates NF profile changes in advance to identify when firewall rule updates are required, allowing for efficient, targeted updates rather than continuous manual synchronization, thereby reducing time consumption while maintaining accuracy.
3Productivity
If automated firewall management is implemented, then productivity increases, but system complexity increases
Solution Approach 1:
The NRF/SCP performs multiple functions within a single system component: it manages NF profile storage, monitors for changes, determines firewall update requirements, and executes rule configuration. By consolidating these diverse functions into the NRF/SCP, the system achieves automated high-productivity firewall management without proportionally increasing overall system complexity.
Solution Approach 2:
The NRF/SCP acts as an intermediary between the NF profile management system and the firewall configuration system. This intermediary component automatically translates NF profile changes into appropriate firewall rule updates, simplifying the interaction between different system parts and enabling automated management without requiring complex direct integration between all components.
4Reliability
If firewall rules are updated manually, then configuration control is maintained, but errors increase
Solution Approach 1:
The system enables automatic self-configuration of firewall rules by the NRF/SCP based on NF profile changes. The NRF/SCP automatically determines when firewall rule updates are needed and performs the configuration without manual intervention, allowing the system to serve itself rather than requiring operator manual configuration for each topology change.
Solution Approach 2:
The system establishes a feedback mechanism where the NRF/SCP continuously monitors NF profile changes and automatically triggers firewall rule updates in response. This closed-loop feedback ensures that firewall configuration automatically adapts to network topology changes, eliminating the need for manual reconfiguration and reducing errors.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method for automatically managing a platform firewall using a network function (NF) repository function (NRF) or service communications proxy (SCR) includes receiving message relating to registering, updating or deregistering an NF profile in an NF profiles database separate from a platform firewall. The method further includes determining that the registering, updating, or deregistering of the NF profile requires a change to a firewall rules configuration of the platform firewall. The method further includes, in response to determining that the registering, updating, or deregistering of the NF profile requires a change to the firewall rules configuration of the platform firewall, automatically updating, by the NRF or SCR, the firewall rules configuration of the platform firewall.