US2022329529A1PendingUtilityA1

5g filters for virtual network functions

Assignee: AT & T MOBILITY II LLCPriority: Jul 23, 2019Filed: Jun 28, 2022Published: Oct 13, 2022
Est. expiryJul 23, 2039(~13 yrs left)· nominal 20-yr term from priority
Inventors:Arturo Maria
H04L 47/20H04L 43/16H04L 47/32H04L 41/0895H04L 41/40H04L 45/64H04L 43/0876H04L 41/0631H04L 63/0263H04L 67/12H04L 43/0882H04L 63/20H04L 41/0806
63
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Security filters may protect communication and data traversing and communicating between programs in a hosted container system. In addition, an orchestration system may specifically address the creation and behavior of security filters that manage the behavior of virtual network functions residing in containers.

Claims

exact text as granted — not AI-modified
What is claimed: 
     
         1 . A method comprising:
 obtaining, by a processor, an alert associated with a first virtual network function of a plurality of virtual network functions on a first worker node; and   obtaining, by the processor, security rules for data traffic associated with the first virtual network function, wherein the security rules:
 allow, by a filter for the first worker node, first data traffic of the data traffic based on an identification of the first data traffic as being a packet, 
 deny, by the filter, second data traffic of the data traffic based on an identification of the second data traffic as being of a type that is different from a packet, 
 allow, by the filter, third data traffic of the data traffic based on the third data traffic being from a second virtual network function of the plurality of virtual network functions within the first worker node, and 
 deny, by the filter, fourth data traffic of the data traffic based on the fourth data traffic being from a third virtual network function. 
   
     
     
         2 . The method of  claim 1 , wherein the third virtual network function is within a second worker node. 
     
     
         3 . The method of  claim 1 , wherein the security rules:
 deny, by the filter, fifth data traffic of the data traffic based on the fifth data traffic being destined for the second virtual network function.   
     
     
         4 . The method of  claim 1 , wherein the security rules:
 allow, by the filter, fifth data traffic of the data traffic based on the fifth data traffic being destined for the third virtual network function.   
     
     
         5 . The method of  claim 1 , wherein the security rules:
 allow, by the filter, fifth data traffic of the data traffic based on the fifth data traffic being destined for the third virtual network function.   
     
     
         6 . The method of  claim 5 , wherein the security rules:
 deny, by the filter, sixth data traffic of the data traffic based on the sixth data traffic being destined for the third virtual network function.   
     
     
         7 . The method of  claim 1 , wherein the security rules:
 allow, by the filter, fifth data traffic of the data traffic based on the fifth data traffic being from a fourth virtual network function that is within a second worker node,   deny, by the filter, sixth data traffic of the data traffic based on the sixth data traffic being destined for the fourth virtual network function.   
     
     
         8 . The method of  claim 7 , wherein the security rules:
 deny, by the filter, seventh data traffic of the data traffic based on the seventh data traffic being from a fifth virtual network function that is within a third worker node,   deny, by the filter, eighth data traffic of the data traffic based on the eighth data traffic being destined for the fifth virtual network function,   allow, by the filter, ninth data traffic of the data traffic based on the ninth data traffic being from a sixth virtual network function that is within the third worker node, and   allow, by the filter, tenth data traffic of the data traffic based on the tenth data traffic being destined for the sixth virtual network function.   
     
     
         9 . An apparatus comprising:
 a processor; and   a memory coupled with the processor, the memory storing executable instructions that when executed by the processor cause the processor to effectuate operations comprising:
 obtaining a request to create a first virtual network function of a plurality of virtual network functions on a first worker node; 
 based on the obtaining of the request, obtaining security rules for data traffic associated with the first virtual network function; and 
 based on the security rules:
 denying, by a filter, first data traffic of the data traffic based on an identification of the first data traffic as being a packet, 
 allowing, by the filter, second data traffic of the data traffic based on an identification of the second data traffic as being of a type that is different from a packet, 
 allowing, by the filter, third data traffic of the data traffic based on the third data traffic being from a second virtual network function of the plurality of virtual network functions within the first worker node, and 
 denying, by the filter, fourth data traffic of the data traffic based on the fourth data traffic being destined for the second virtual network function. 
 
   
     
     
         10 . The apparatus of  claim 9 , wherein the first virtual network function comprises a serving gateway. 
     
     
         11 . The apparatus of  claim 9 , wherein the first virtual network function comprises a packet data network gateway. 
     
     
         12 . The apparatus of  claim 9 , wherein the first worker node is associated with a connected car. 
     
     
         13 . The apparatus of  claim 9 , the operations further comprising:
 detecting that data traffic of a first type for the first virtual network function reaches a first threshold;   based on the detecting that the data traffic of the first type reaches the first threshold, generating an alert associated with data traffic security; and   based on the alert, sending a message to update the security rules to restrict traffic for data traffic of a third virtual network function.   
     
     
         14 . The apparatus of  claim 9 , the operations further comprising:
 detecting that data traffic of a first type for the first virtual network function reaches a first threshold; and   based on the detecting that the data traffic of the first type reaches the first threshold, sending a message to update the security rules for data traffic of the second virtual network function, wherein the second virtual network function is based on an image of the first virtual network function.   
     
     
         15 . The apparatus of  claim 9 , the operations further comprising:
 detecting that data traffic of a first type for the first virtual network function reaches a first threshold; and   based on the detecting that the data traffic of the first type reaches the first threshold, sending a message to update the security rules for data traffic of a third virtual network function, wherein the third virtual network function operates in a second worker node.   
     
     
         16 . A non-transitory computer readable storage medium storing computer executable instructions that when executed by a computing device cause said computing device to effectuate operations comprising:
 updating a filter for a first node for a first virtual network function of a plurality of virtual network functions, wherein the filter filters data traffic from or to the plurality of virtual network functions within the first node, and wherein the first node is a virtual machine;   obtaining security rules for data traffic associated with the first virtual network function, wherein the security rules are updated periodically based on factors that comprise:
 intrusions detected by a remote user plane orchestrator or remote filters, and 
 throughput or processing associated with an application reaches a threshold level that is determined to negatively impact performance; and 
   based on the security rules:
 allowing, by the filter, first data traffic of the data traffic based on an identification of the first data traffic as being a packet, 
 denying, by the filter, second data traffic of the data traffic based on an identification of the second data traffic as being of a type that is different from a packet, 
 allowing, by the filter, third data traffic of the data traffic based on the third data traffic being from a second virtual network function of the plurality of virtual network functions within the first node, 
 allowing, by the filter, fourth data traffic of the data traffic based on the fourth data traffic being destined for a third virtual network function of the plurality of virtual network functions. 
   
     
     
         17 . The non-transitory computer readable storage medium of  claim 16 , wherein the first virtual network function comprises a serving gateway. 
     
     
         18 . The non-transitory computer readable storage medium of  claim 16 , wherein the first virtual network function comprises a packet data network gateway. 
     
     
         19 . The non-transitory computer readable storage medium of  claim 16 , wherein the first node is associated with a connected car. 
     
     
         20 . The non-transitory computer readable storage medium of  claim 16 , the operations further comprising:
 detecting that data traffic of a first type for the first virtual network function reaches a first threshold; and   based on the detecting that the data traffic of the first type reaches the first threshold, sending a message to update the security rules for data traffic of the second virtual network function.

Join the waitlist — get patent alerts

Track US2022329529A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.