NRF SCP Automatic Platform Firewall Rule Synchronization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Configuring and maintaining platform firewalls in 5G telecommunications networks is labor-intensive and prone to errors, particularly in synchronizing firewall rules with changes in Network Function (NF) profiles.

Innovation Solution

A method and system for automatically managing platform firewalls using a Network Function Repository Function (NRF) or Service Communication Proxy (SCP), which receives messages related to NF profile registrations, updates, or deregistrations and automatically updates the firewall rules configuration accordingly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual configuration of platform firewall rules is used, then configuration simplicity is maintained, but labor intensity increases and errors occur

Engineering Contradiction:
Improveconfiguration simplicityVSAvoidconfiguration efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The system enables automatic self-configuration of firewall rules by the NRF/SCP based on NF profile changes. The NRF/SCP automatically determines when firewall rule updates are needed and performs the configuration without manual intervention, allowing the system to serve itself rather than requiring operator manual configuration for each topology change.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system establishes a feedback mechanism where the NRF/SCP continuously monitors NF profile changes and automatically triggers firewall rule updates in response. This closed-loop feedback ensures that firewall configuration automatically adapts to network topology changes, eliminating the need for manual reconfiguration and reducing errors.

Inventive Principle:
Principle #23Feedback

2Reliability

If manual synchronization of firewall rules with NF profiles is performed, then control over configuration is maintained, but time consumption increases

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidsynchronization time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements continuous automatic synchronization between NF profiles and firewall rules. The NRF/SCP continuously monitors for profile changes and maintains ongoing updates to firewall rules, ensuring that the configuration remains current without interruption. This eliminates the periodic manual synchronization process that causes time loss and potential inaccuracies.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system performs preliminary determination of whether firewall rule changes are needed before actually updating the rules. The NRF/SCP evaluates NF profile changes in advance to identify when firewall rule updates are required, allowing for efficient, targeted updates rather than continuous manual synchronization, thereby reducing time consumption while maintaining accuracy.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If automated firewall management is implemented, then productivity increases, but system complexity increases

Engineering Contradiction:
Improveconfiguration efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The NRF/SCP performs multiple functions within a single system component: it manages NF profile storage, monitors for changes, determines firewall update requirements, and executes rule configuration. By consolidating these diverse functions into the NRF/SCP, the system achieves automated high-productivity firewall management without proportionally increasing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The NRF/SCP acts as an intermediary between the NF profile management system and the firewall configuration system. This intermediary component automatically translates NF profile changes into appropriate firewall rule updates, simplifying the interaction between different system parts and enabling automated management without requiring complex direct integration between all components.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If firewall rules are updated manually, then configuration control is maintained, but errors increase

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidoperation simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables automatic self-configuration of firewall rules by the NRF/SCP based on NF profile changes. The NRF/SCP automatically determines when firewall rule updates are needed and performs the configuration without manual intervention, allowing the system to serve itself rather than requiring operator manual configuration for each topology change.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system establishes a feedback mechanism where the NRF/SCP continuously monitors NF profile changes and automatically triggers firewall rule updates in response. This closed-loop feedback ensures that firewall configuration automatically adapts to network topology changes, eliminating the need for manual reconfiguration and reducing errors.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP4335081B1Methods, systems, and computer readable media for platform firewall management by network function (NF) repository function (NRF) or service communications proxy (SCP)
Publication Date: 2025.01.22 ORACLE INT CORP
  • EP4335081B1 patent drawingFigure 1
  • EP4335081B1 patent drawingFigure 2
  • EP4335081B1 patent drawingFigure 3

AI summary

A method for automatically managing a platform firewall using a network function (NF) repository function (NRF) or service communications proxy (SCR) includes receiving message relating to registering, updating or deregistering an NF profile in an NF profiles database separate from a platform firewall. The method further includes determining that the registering, updating, or deregistering of the NF profile requires a change to a firewall rules configuration of the platform firewall. The method further includes, in response to determining that the registering, updating, or deregistering of the NF profile requires a change to the firewall rules configuration of the platform firewall, automatically updating, by the NRF or SCR, the firewall rules configuration of the platform firewall.