Virtual Firewall Service Chaining in Compact Private Mobile Cores

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication networks, particularly 5G cellular networks, face challenges in implementing effective security measures due to the compact nature of private mobile cores, which makes it infeasible to place external firewalls at all desired network traffic interfaces, leaving them vulnerable to external and internal malicious traffic.

Innovation Solution

Deploying a virtual firewall within the private mobile core by service-chaining network functions, utilizing a third virtual machine that implements firewall functions, and establishing static routes to direct network traffic through this machine for threat analysis and security management, including the use of machine learning techniques for encrypted traffic detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If external firewalls are deployed at all desired network traffic interfaces, then security coverage is improved, but device complexity and hardware requirements increase beyond what is feasible in compact private mobile cores

Engineering Contradiction:
Improvesecurity coverageVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the firewall function with the UPF by deploying both as virtual network functions on the same host server. The third virtual machine implementing firewall functions is service-chained to the UPF, allowing security inspection to be integrated within the compact private mobile core architecture without requiring separate external firewall hardware at multiple interfaces

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The host server serves multiple functions by hosting both the UPF and firewall virtual machines, creating a multi-functional platform that provides both user plane routing and security inspection capabilities within a single physical infrastructure, reducing overall hardware requirements

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Object-affected harmful factors

If multiple external firewalls are deployed to cover all network interfaces, then security against malicious traffic is improved, but the compact private mobile core architecture cannot accommodate the additional hardware

Engineering Contradiction:
Improvemalicious traffic protectionVSAvoidhardware footprint
Core Design Contradiction:
Object-affected harmful factorsVSVolume of stationary object

Solution Approach 1:

The firewall capability is merged into the existing UPF infrastructure by deploying both as virtual network functions on the same host server. This integration allows security inspection to be embedded within the compact private mobile core, providing malicious traffic protection without expanding the physical hardware footprint

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent uses virtualization to create virtual copies of network functions. The third virtual machine implementing firewall functions is service-chained to the UPF, allowing security inspection capabilities to be replicated virtually rather than requiring separate physical firewall devices for each network interface

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20260064456A1Virtual firewall for use in a private mobile core
Publication Date: 2026.03.05 AT&T INTELLECTUAL PROPERTY I L P
  • US20260064456A1 patent drawing
  • US20260064456A1 patent drawing
  • US20260064456A1 patent drawing

AI summary

Aspects of the subject disclosure may include, for example, a method that includes deploying a first virtual machine configured to implement a plurality of control plane network functions in a wireless network, deploying a second virtual machine configured to implement a user plane function in the wireless network, deploying a third virtual machine configured to implement firewall functions, and deploying the first virtual machine, the second virtual machine and the third virtual machine on an on-premises host server. Other embodiments are disclosed.